ax-extract-workflow-cn

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the local ax command-line tool to retrieve session history, commit details, and activity logs. These operations are conducted locally and align with the skill's primary function of workflow reconstruction.
  • [PROMPT_INJECTION]: The skill ingests historical session data retrieved via the ax tool (e.g., ax sessions show). This creates an indirect prompt injection surface where content from previous agent interactions could influence the current session. The instructions lack explicit boundary markers or sanitization requirements for this ingested content, although they do encourage factual reporting and citing evidence.
  • Ingestion points: ax recall, ax sessions near, ax sessions show output.
  • Boundary markers: Absent.
  • Capability inventory: Execution of ax shell commands to query and display data.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 03:36 PM
Security Audit — agent-trust-hub — ax-extract-workflow-cn