session-debrief
Fail
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs shell command execution by interpolating external inputs into shell strings. Specifically, the
<sessionId>provided in the input is used directly in commands like${POLYGRAPH_CLI:-polygraph} session show --details <sessionId>and${POLYGRAPH_CLI:-polygraph} session logs -s <sessionId>. Without proper sanitization of the session ID, an attacker could provide a malicious string containing command separators (e.g.,;,&&, or backticks) to execute arbitrary shell commands in the agent's environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external transcripts, creating a risk of indirect prompt injection.\n - Ingestion points: The skill reads raw transcripts and logs from past Polygraph sessions via the
session logscommand as described inSKILL.md.\n - Boundary markers: There are no boundary markers or clear delimiters specified to separate the analyzed log content from the agent's instructions, nor are there instructions to ignore instructions found within the logs.\n
- Capability inventory: The agent has the ability to execute shell commands via the
polygraphCLI and to spawn subagents for further tasks.\n - Sanitization: No sanitization, filtering, or escaping is performed on the ingested logs before they are processed by the LLM.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates and executes logic by spawning subagents for concurrent session debriefing. It copies prompt instructions and untrusted input data into the subagent context at runtime, which increases the potential for instruction manipulation or multi-step injection chains.
Recommendations
- AI detected serious security threats
Audit Metadata