ce-product-pulse

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external telemetry providers (PostHog, Mixpanel, Sentry) and databases to generate reports, creating a surface for potential instruction injection via polluted telemetry. \n
  • Ingestion points: External query results in references/run.md and references/report-template.md. \n
  • Boundary markers: Absent. External data is interpolated into the report template without specific delimiters or instructions to ignore embedded content. \n
  • Capability inventory: Includes Write access to local files and Bash access. \n
  • Sanitization: The skill mandates strict PII removal and anonymization of session data before report persistence. \n- [COMMAND_EXECUTION]: The skill utilizes the shell for environment discovery and configuration management. \n
  • Evidence: Executes git rev-parse --show-toplevel to resolve paths for configuration storage and pulse reports. \n- [DATA_EXFILTRATION]: The skill interacts with sensitive telemetry and database records. \n
  • Evidence: Accesses tracing logs and analytics data. \n
  • Mitigation: Implements a strict read-only policy, refuses database connections with write access, and prevents PII from being saved to the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:30 AM
Security Audit — agent-trust-hub — ce-product-pulse