agent-session-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill proactively defines security guardrails by instructing the agent to redact secrets from logs and code snippets, and to avoid committing sensitive files like .env or private keys.
  • [SAFE]: The Git and PR policy enforces user oversight by requiring explicit confirmation for commits, pushes, and pull request creation, preventing unauthorized changes to the codebase.
  • [SAFE]: The version check protocol utilizes a standard, non-executable command (npm view) to query version metadata from the public NPM registry, which is a safe method for update notification.
  • [INDIRECT_PROMPT_INJECTION]: The skill builds context from external sources like the .opencode/.kit-version file and general project structure, creating a minor surface for indirect prompt injection if those files are maliciously modified.
  • Ingestion points: Reads project-specific metadata from .opencode/.kit-version and performs analysis of the local project directory to build a session mental model.
  • Boundary markers: None identified for the ingested project metadata.
  • Capability inventory: The skill uses shell command execution (npm view) to check for package updates.
  • Sanitization: No explicit sanitization or validation of the version string is defined before comparison.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — agent-session-workflow