sync-claude-sessions

Warn

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The Python script scripts/claude-sessions utilizes subprocess.run to call the fzf binary for interactive session selection and os.execvp to invoke the claude CLI for session resumption.
  • [COMMAND_EXECUTION]: The workflows/log-session.md file instructs the agent to perform dynamic code execution by generating and running JavaScript code snippets via the obsidian eval command to programmatically update vault metadata.
  • [COMMAND_EXECUTION]: The skill provides configuration guidance in workflows/setup.md to modify ~/.claude/settings.json, adding persistence hooks (UserPromptSubmit and Stop) that automatically trigger the sync script during the agent's operation lifecycle.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 06:42 AM