session-resume

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes standard git utilities to synchronize state. The skill runs git status and git branch to validate that the local repository matches the handoff context provided in .kiro/ documentation.
  • [PROMPT_INJECTION]: Presents an indirect prompt injection surface through data ingestion. The skill reads and summarizes content from .kiro/context/ and session-handoff.md which could contain untrusted data.
  • Ingestion points: SKILL.md (Workflow steps 1-4).
  • Boundary markers: Absent; no delimiters are used to separate external file content from agent instructions.
  • Capability inventory: Limited to local file system reads and standard git operations.
  • Sanitization: The skill does not implement validation or escaping for the content loaded from external files.
  • [COMMAND_EXECUTION]: Provides manual configuration instructions to the user. The skill suggests using ln -sf to manage symlinks for steering files and includes a manual checklist recommendation to use /tools trust-all to bypass confirmation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — session-resume