span-file-export
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a mechanism for AI agents to ingest log and span files from
~/.sf/vscode-spans/. These files contain abodyfield for log messages that may include untrusted data from the user's workspace or external sources. An agent processing this data without proper sanitization is susceptible to indirect prompt injection instructions embedded in the logs.\n - Ingestion points: The agent is instructed to read JSONL files from the
~/.sf/vscode-spans/directory.\n - Boundary markers: The JSONL format provides field-level separation (e.g.,
body,kind), but the skill does not define specific delimiters to isolate potential instructions within the log body.\n - Capability inventory: The skill provides the agent with file management capabilities, including listing and deleting telemetry files via shell commands.\n
- Sanitization: No methods for filtering or sanitizing the log content are mentioned.\n- [COMMAND_EXECUTION]: The instructions provide shell commands for the agent to find and manage telemetry files, specifically
ls -lt ~/.sf/vscode-spans/ | head -1andrm -rf ~/.sf/vscode-spans/. While limited to the telemetry directory, these represent executable commands provided to the agent.
Audit Metadata