review-conversation
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a set of CLI commands for viewing and filtering JSONL session files. It uses established libraries like
typer,rich, andloguru. - [DATA_EXPOSURE_&_EXFILTRATION]: The skill accesses files in
~/.pi/assistant/(shadow.jsonl,shadow_deltas.jsonl) andsparta-stress-test/results/sessions/. These paths are consistent with the skill's stated purpose of reviewing assistant session logs and do not indicate unauthorized data harvesting. - [COMMAND_EXECUTION]: The
run.shscript executes the Python entry point usinguv run. There are no instances of arbitrary shell command execution or user-input injection into shell contexts. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill relies on local dependencies and internal compositions.
- [OBFUSCATION]: The code is well-structured and documented. The
mermaid.pyutility properly escapes user-supplied text for diagram generation using HTML entities to prevent rendering errors, which is a security best practice. - [PROMPT_INJECTION]: There are no instructions or patterns that attempt to override agent safety guardrails.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests and displays untrusted conversation data, it does so through structured rendering and plain markdown (
briefcommand) which reduces the risk of the agent misinterpreting data as instructions. It lacks high-privilege write capabilities that would make it a significant injection target.
Audit Metadata