discover-event-surfaces
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a structured, non-malicious workflow to assist with analytics instrumentation.
- [COMMAND_EXECUTION]: Employs vendor-provided tools get_context and get_events to interface with the Amplitude platform.
- [DATA_EXPOSURE]: Accesses local source code files to analyze user-facing changes and map interaction sequences, which is required for the skill's primary purpose.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it ingests untrusted data from the change_brief and local source code files. It lacks explicit boundary markers or sanitization for this content. However, its capabilities are limited to querying event metadata and generating YAML suggestions, resulting in minimal security risk.
Audit Metadata