discover-analytics-patterns

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill reads instructions from a local configuration file (.amplitude/instrumentation-agent-context.md) and treats them as 'customer directives' that override its internal logic. This ingestion point lacks explicit boundary markers or sanitization, creating a surface for indirect prompt injection where a maliciously crafted file could attempt to influence agent behavior.
  • [COMMAND_EXECUTION]: The skill uses search tools to run grep commands across the repository to identify analytics SDK call sites, import statements, and custom wrapper functions. This is a standard and necessary function for analyzing coding patterns.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with an Amplitude MCP server to fetch event and property metadata. This external data retrieval is used to ensure instrumentation consistency and is aligned with the vendor's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:51 AM
Security Audit — agent-trust-hub — discover-analytics-patterns