session-retrospective

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the gh CLI and git commands to interact with GitHub repositories. The Python script scripts/create_issues.py uses subprocess.run to execute these system binaries for issue management.
  • [CREDENTIALS_UNSAFE]: The skill includes instructions and code to extract GitHub access tokens from the local git configuration (git remote get-url). While used for legitimate automation within the author's workflow, this pattern programmatically accesses sensitive authentication data.
  • [DATA_EXFILTRATION]: The skill transmits session-derived data (issue titles and bodies) to an external GitHub repository (minicoohei/ai-agent-camp). This aligns with the skill's stated purpose and targets a well-known service associated with the author.
  • [PROMPT_INJECTION]: The skill processes session history to generate issues, which presents a surface for indirect prompt injection. However, the workflow includes a mandatory user confirmation step ('Phase 3: User Confirmation') where the user must approve the content before any issues are registered, significantly mitigating the risk of unauthorized or malicious actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — session-retrospective