dream-insights

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses a shell command to identify the most recent journal file in the local data directory.
  • [DATA_EXPOSURE]: Accesses journal entries stored in the application-specific directory ~/.claude/dream/journal/ to display them to the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill displays contents from external files, which represents a potential surface for indirect injection if those logs contain untrusted content.
  • Ingestion points: Journal files in ~/.claude/dream/journal/.
  • Boundary markers: No delimiters or ignore instructions are used for the displayed content.
  • Capability inventory: Read tool, Bash (ls, head).
  • Sanitization: No sanitization is performed on the journal content before display.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — dream-insights