pre-session-end

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes untrusted session history to propose new skills, creating an indirect prompt injection risk where malicious session content could be converted into persistent instructions. 1. Ingestion points: Session history and chat history. 2. Boundary markers: Includes a mandatory 'Never auto-apply' human-in-the-loop requirement. 3. Capability inventory: File creation in ~/.claude/skills/learned/ and modification of ~/.claude/settings.json. 4. Sanitization: No automated content validation.
  • [DATA_EXFILTRATION]: Accesses the agent's global configuration file ~/.claude/settings.json and project-specific settings, which contain permission scopes and environment data.
  • [COMMAND_EXECUTION]: Facilitates the promotion of local tool permissions (e.g., Bash, Docker) to a global scope, which is a privilege management activity that increases the potential impact of an attack if broad permissions are accidentally globalized.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 01:21 AM
Security Audit — agent-trust-hub — pre-session-end