remediate-workspace-session-kill
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements mandatory human-in-the-loop (HITL) guardrails. The --apply mode requires specific environment variables for an incident ID and an authorized approver, ensuring that remediation actions are tied to a formal incident response process.
- [SAFE]: A strict domain boundary is enforced. The skill requires an explicit allow-list of domains and will refuse to operate on any user identity that falls outside of the authorized WORKSPACE_SESSION_KILL_ALLOWED_DOMAINS configuration.
- [SAFE]: The code includes a protected-principal deny-list to prevent accidental or malicious termination of critical sessions, such as those belonging to domain administrators, service accounts, or emergency 'break-glass' identities.
- [SAFE]: The skill performs dual-auditing, writing records to both AWS DynamoDB and KMS-encrypted S3 buckets before and after each remediation step, providing a tamper-evident audit trail for identity-write operations.
- [SAFE]: Network egress and API interactions are limited to well-known and trusted technology providers, specifically Google Admin SDK and AWS services.
Audit Metadata