dev-session-debug
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [Telemetry Data Access]: The skill enables inspection of session.db and session.bodies files, which contain a record of session activities such as model prompts, tool arguments, and network events. This level of access is intended for deep debugging and forensics of the telemetry pipeline.
- [Security and Credential Logging]: The database schema tracks security rule matches and credential references (credential_ref). This ensures auditability but indicates that diagnostic logs contain references to security operations.
- [Local Diagnostic Scripts]: The skill utilizes internal Python scripts (e.g., list_sessions.py, check_session.py) for session inspection. These commands are part of the platform diagnostic toolkit and run within the local project environment.
- [Untrusted Data Processing]: The skill processes data from session ledgers which may include external content (Ingestion point: session.db, session.bodies). While the proxy hashes certain headers (Sanitization), the analysis of these logs lacks explicit boundary markers to ignore embedded instructions (Boundary markers: absent). Combined with the capability to execute local scripts (Capability inventory: python3), this presents a surface for indirect prompt injection, though it is consistent with the skill's diagnostic purpose.
Audit Metadata