investigate-ai-session

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data originating from external users in past sessions.
  • Ingestion points: Conversation transcripts are retrieved via Amplitude:get_agent_analytics_conversation and execution traces via Amplitude:query_agent_analytics_spans in Step 2.
  • Boundary markers: No specific delimiters or instructions are provided to the agent to ignore or isolate instructions found within the historical transcripts.
  • Capability inventory: The agent has capabilities to query further analytics data, search conversations, and group session data based on findings from the ingested content.
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from session transcripts before it is presented to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 05:11 PM
Security Audit — agent-trust-hub — investigate-ai-session