session-debrief

Fail

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell command execution by interpolating external inputs into shell strings. Specifically, the <sessionId> provided in the input is used directly in commands like ${POLYGRAPH_CLI:-polygraph} session show --details <sessionId> and ${POLYGRAPH_CLI:-polygraph} session logs -s <sessionId>. Without proper sanitization of the session ID, an attacker could provide a malicious string containing command separators (e.g., ;, &&, or backticks) to execute arbitrary shell commands in the agent's environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external transcripts, creating a risk of indirect prompt injection.\n
  • Ingestion points: The skill reads raw transcripts and logs from past Polygraph sessions via the session logs command as described in SKILL.md.\n
  • Boundary markers: There are no boundary markers or clear delimiters specified to separate the analyzed log content from the agent's instructions, nor are there instructions to ignore instructions found within the logs.\n
  • Capability inventory: The agent has the ability to execute shell commands via the polygraph CLI and to spawn subagents for further tasks.\n
  • Sanitization: No sanitization, filtering, or escaping is performed on the ingested logs before they are processed by the LLM.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates and executes logic by spawning subagents for concurrent session debriefing. It copies prompt instructions and untrusted input data into the subagent context at runtime, which increases the potential for instruction manipulation or multi-step injection chains.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 2, 2026, 04:38 AM
Security Audit — agent-trust-hub — session-debrief