investigate-ai-session
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data originating from external users in past sessions.
- Ingestion points: Conversation transcripts are retrieved via
Amplitude:get_agent_analytics_conversationand execution traces viaAmplitude:query_agent_analytics_spansin Step 2. - Boundary markers: No specific delimiters or instructions are provided to the agent to ignore or isolate instructions found within the historical transcripts.
- Capability inventory: The agent has capabilities to query further analytics data, search conversations, and group session data based on findings from the ingested content.
- Sanitization: There is no evidence of sanitization or filtering of the content retrieved from session transcripts before it is presented to the agent's context.
Audit Metadata