ai-coding-agents-sessions
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes processes for session restoration and transcript rehydration, which inherently involve ingesting untrusted data from historical agent turns or tool outputs into the current context.
- Ingestion points: Transcripts stored in JSONL format, session state files (
state.json), and SQLite indices are identified as sources for session re-entry. - Boundary markers: The guidance explicitly mandates user confirmation for cross-project recovery and worktree adoption to prevent unintended context transitions.
- Capability inventory: The agents described are designed to have capabilities for file system modification, shell command execution, and subagent orchestration.
- Sanitization: The skill recommends rebuilding environment-dependent state and clearing discovery caches upon resume to ensure the agent operates on fresh, verified environment data.
- [DATA_EXPOSURE]: The skill documents standard storage paths for session metadata and transcripts (e.g.,
~/.claude/jobs/,~/.codex/config.toml). These references are strictly descriptive and provided for technical implementation guidance; no attempts to exfiltrate these files or hardcoded credentials were found.
Audit Metadata