monitor-experiments

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources via Amplitude:get_feedback_insights. This data originates from user feedback and could theoretically contain instructions intended to influence the agent. However, the skill lacks high-privilege capabilities (such as shell execution, network exfiltration, or file system writing) that could be exploited by such content, and it focuses on summarizing themes for reporting purposes.
  • [SAFE]: The skill exclusively utilizes vendor-provided tools (e.g., Amplitude:search, Amplitude:get_experiments, Amplitude:query_experiment) that correspond to the author's platform. These operations are strictly aligned with the skill's primary purpose of experiment monitoring and do not exhibit unauthorized data access or exfiltration patterns.
  • [SAFE]: The instructions incorporate data handling best practices, such as masking internal identifiers (metric IDs) from the end user and implementing filtering logic to manage API response sizes and stay within safe execution limits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:52 PM
Security Audit — agent-trust-hub — monitor-experiments