session-wrap

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git status and git diff commands to analyze the current workspace state. These are standard developer operations and do not involve unauthorized access or dangerous parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session activity data (tasks performed, decisions made, file changes) to generate analysis. While this creates a potential surface for indirect injection if malicious content exists in the processed work history, the risk is mitigated by a multi-agent validation step and the requirement for explicit user approval of all proposed actions.
  • [DYNAMIC_EXECUTION]: The workflow includes an option to generate new automation scripts or agent skills based on detected patterns. This functionality is intended for developer productivity and is gated behind an interactive multi-select menu, ensuring no code is created or executed without user intervention.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:13 PM
Security Audit — agent-trust-hub — session-wrap