session-tool
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
bun session-toolCLI command to list, read, and search sessions. - [EXTERNAL_DOWNLOADS]: The tool depends on the
@blogic-cz/agent-toolspackage, which is a resource provided by the author (blogic-cz). - [DATA_EXPOSURE]: The skill is designed to read local session storage for Claude Code and OpenCode, which contains sensitive logs of past interactions.
- [PROMPT_INJECTION]: A surface for indirect prompt injection exists as the tool processes past conversation history. 1. Ingestion points: Local session storage files for OpenCode and Claude Code. 2. Boundary markers: Absent from the provided instructions. 3. Capability inventory: Execution of local CLI tool via
bun. 4. Sanitization: No sanitization or filtering is mentioned in the skill instructions.
Audit Metadata