life-execute-session

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a highly restrictive 'secretary' role that limits its own autonomy. It includes an 'Iron Law' and 'Hybrid ban' that prevent the agent from performing focus work, modifying external file trees, or creating product artifacts (like code or design specs) unless an explicit, scoped 'grant' is provided by the user for that specific turn.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided reports during the session completion phase. This represents a potential indirect injection surface, though the risk is minimized by the skill's defensive instruction set.
  • Ingestion points: User report input is ingested in SKILL.md under the 'End' section.
  • Boundary markers: Data is directed into specific log slots (e.g., duration, energy_after, outcome_session).
  • Capability inventory: The skill is limited to writing session logs and handoffs; it explicitly forbids external file edits and ungranted product work.
  • Sanitization: No explicit sanitization of the report text is described, but the agent's role is strictly limited to logging and proposing next steps based on the report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:22 AM
Security Audit — agent-trust-hub — life-execute-session