session-search

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process raw data from previous agent interactions, including Pi session logs and agent-session-capture backups. This content is inherently untrusted and could contain malicious instructions embedded by external actors or generated in prior sessions.
  • Ingestion points: Processes 'raw local/remote Pi sessions', 'transcript bodies', and 'agent-session-capture-backup' files.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the retrieved session data.
  • Capability inventory: The skill possesses the ability to execute an 'existing repair script' and perform 'environment repair' mutations based on session analysis.
  • Sanitization: No sanitization or validation routines are specified for the session content before it is re-integrated into the agent's context or used to drive repairs.
  • [COMMAND_EXECUTION]: The instructions explicitly mention the use of an 'existing repair script' and the performance of 'environment repair' and 'replay' mutations. This indicates the skill is intended to facilitate the execution of local scripts and system modifications based on session diagnostics.
  • [DATA_EXFILTRATION]: The skill is authorized to access 'remote Pi sessions' and utilize a 'saved memory connection' to aggregate conversation history. While this is consistent with its stated purpose of session search and recall, it involves the handling and potential movement of sensitive interaction data across local and remote contexts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — session-search