session-retrospective
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
ghCLI andgitcommands to interact with GitHub repositories. The Python scriptscripts/create_issues.pyusessubprocess.runto execute these system binaries for issue management. - [CREDENTIALS_UNSAFE]: The skill includes instructions and code to extract GitHub access tokens from the local git configuration (
git remote get-url). While used for legitimate automation within the author's workflow, this pattern programmatically accesses sensitive authentication data. - [DATA_EXFILTRATION]: The skill transmits session-derived data (issue titles and bodies) to an external GitHub repository (
minicoohei/ai-agent-camp). This aligns with the skill's stated purpose and targets a well-known service associated with the author. - [PROMPT_INJECTION]: The skill processes session history to generate issues, which presents a surface for indirect prompt injection. However, the workflow includes a mandatory user confirmation step ('Phase 3: User Confirmation') where the user must approve the content before any issues are registered, significantly mitigating the risk of unauthorized or malicious actions.
Audit Metadata