project-session-manager
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies extensively on executing shell commands to manage git worktrees and tmux sessions. It interacts with several version control system CLIs including git, jq, gh, jira, az, tea, and glab.
- [PRIVILEGE_ESCALATION]: The skill launches the Claude agent using the
--dangerously-skip-permissionsflag. This flag disables the security sandbox's requirement for user approval on every tool invocation, granting the agent autonomous command execution capabilities within the managed session. - [INDIRECT_PROMPT_INJECTION]: The skill creates a significant surface for indirect prompt injection by fetching untrusted content from external Pull Requests and Issues and immediately launching an autonomous agent on that code.
- Ingestion points: External metadata (titles, descriptions) and file content from providers like GitHub and Jira are written to markdown context files (e.g.,
.psm/review.md) inside the new worktree. - Boundary markers: The context files use standard markdown headers, but they lack explicit instructions or markers to prevent the agent from following malicious commands embedded in the external text.
- Capability inventory: The agent has full shell access through tmux and is configured to bypass tool-approval prompts.
- Sanitization: While the skill sanitizes identifiers for filenames and session IDs, it does not perform deep sanitization of the PR/Issue content before presenting it to the agent as task instructions.
- [EXTERNAL_DOWNLOADS]: The skill fetches data and clones source code from multiple external providers, including GitHub, Jira, Bitbucket, GitLab, Azure DevOps, and Gitea repositories.
Audit Metadata