session-index

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the claude-session-index package via pip. This package is hosted on a public registry and originates from a source not included in the trusted vendor list.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes historical session data which may contain untrusted content from previous interactions. 1. Ingestion points: Data is read from the local SQLite database (/.session-index/sessions.db) and session topic files (/.claude/session-topics/) using the sessions context command. 2. Boundary markers: Absent; the instructions do not define specific delimiters or instructions for the subagent to ignore potentially malicious embedded content. 3. Capability inventory: The skill executes shell commands and spawns subagents to process the ingested data. 4. Sanitization: Absent; there are no documented steps for filtering session content before synthesis.
  • [COMMAND_EXECUTION]: The skill operates by executing the sessions CLI tool via the system shell to perform searches, retrieve context, and generate analytics.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:08 AM
Security Audit — agent-trust-hub — session-index