The audits

Risk

Risk shows what a session wrote outside the workspace β€” exercised, not merely permitted.

Risk is the audit of what a session did that could cause harm. Like Egress, it reports what the session exercised, never what it was permitted β€” an agent writes nothing to the transcript when it asks for approval, so hand-approved and auto-approved work are indistinguishable from the outside. The audit therefore states what ran.

What Risk flags

Risk flags destructive or privileged shell commands β€” for example rm -rf, git reset --hard, forced pushes, curl piped to a shell, sudo, and reads or writes of credential files β€” as HIGH or MED rows stating the reason in plain words.

It also lists the edits that landed outside the workspace β€” something no workspace-relative file list can show, and exactly the kind of change that's easy to miss.

⚠︎
Exercised, not permitted

A HIGH row means the command ran. It does not mean you failed to approve it β€” the transcript can't tell approved from auto-approved. The audit's job is to make sure nothing dangerous ran unseen, whatever the permission path.

Risk closes the Actions view alongside Egress, because both are read off the same stream of actions.