skill-miner

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is configured to scan directories containing sensitive session transcripts, such as ~/.codex/sessions, ~/.claude/projects, and ~/.gemini. These directories store private user inputs, tool interaction logs, and memory summaries which may contain sensitive personal or project information.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from transcript histories, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: scripts/scan_sessions.py reads JSONL and Markdown files from multiple agent-specific history paths.\n
  • Boundary markers: The agent instructions lack specific boundary markers or directives to ignore instructions embedded within the extracted content.\n
  • Capability inventory: The agent has permissions to execute the discovery script and perform file system operations to create new skill directories and metadata files.\n
  • Sanitization: The sanitize function in the provided Python script redacts email addresses and common service tokens, but it does not sanitize for malicious instructions or logical prompt injections.\n- [COMMAND_EXECUTION]: The workflow requires the agent to run a local utility (scripts/scan_sessions.py) that performs broad searches across various subdirectories in the user's home folder.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:19 PM
Security Audit — agent-trust-hub — skill-miner