Oathe Security Badge

Is wrsmith108/session-cleanup-skill safe?

https://github.com/wrsmith108/session-cleanup-skill

99
SAFE

This is a legitimate git repository housekeeping skill that performs end-of-session cleanup tasks like branch management, worktree cleanup, and documentation review. The skill includes appropriate safety guards and user confirmation requirements for destructive operations.

Category Scores

Prompt Injection 100/100 · 30%
Data Exfiltration 95/100 · 25%
Code Execution 100/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 95/100 · 5%

Findings (1)

LOW Accesses project documentation files -5

The skill reads CLAUDE.md and MEMORY.md files as part of its documented housekeeping functionality. While legitimate for its stated purpose of session cleanup, this provides access to project documentation and memory files that could contain sensitive project information.