dream-insights
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses a shell command to identify the most recent journal file in the local data directory.
- [DATA_EXPOSURE]: Accesses journal entries stored in the application-specific directory
~/.claude/dream/journal/to display them to the user. - [INDIRECT_PROMPT_INJECTION]: The skill displays contents from external files, which represents a potential surface for indirect injection if those logs contain untrusted content.
- Ingestion points: Journal files in
~/.claude/dream/journal/. - Boundary markers: No delimiters or ignore instructions are used for the displayed content.
- Capability inventory: Read tool, Bash (ls, head).
- Sanitization: No sanitization is performed on the journal content before display.
Audit Metadata