session-resume
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes standard git utilities to synchronize state. The skill runs
git statusandgit branchto validate that the local repository matches the handoff context provided in.kiro/documentation. - [PROMPT_INJECTION]: Presents an indirect prompt injection surface through data ingestion. The skill reads and summarizes content from
.kiro/context/andsession-handoff.mdwhich could contain untrusted data. - Ingestion points: SKILL.md (Workflow steps 1-4).
- Boundary markers: Absent; no delimiters are used to separate external file content from agent instructions.
- Capability inventory: Limited to local file system reads and standard git operations.
- Sanitization: The skill does not implement validation or escaping for the content loaded from external files.
- [COMMAND_EXECUTION]: Provides manual configuration instructions to the user. The skill suggests using
ln -sfto manage symlinks for steering files and includes a manual checklist recommendation to use/tools trust-allto bypass confirmation prompts.
Audit Metadata