review-conversation

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a set of CLI commands for viewing and filtering JSONL session files. It uses established libraries like typer, rich, and loguru.
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill accesses files in ~/.pi/assistant/ (shadow.jsonl, shadow_deltas.jsonl) and sparta-stress-test/results/sessions/. These paths are consistent with the skill's stated purpose of reviewing assistant session logs and do not indicate unauthorized data harvesting.
  • [COMMAND_EXECUTION]: The run.sh script executes the Python entry point using uv run. There are no instances of arbitrary shell command execution or user-input injection into shell contexts.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill relies on local dependencies and internal compositions.
  • [OBFUSCATION]: The code is well-structured and documented. The mermaid.py utility properly escapes user-supplied text for diagram generation using HTML entities to prevent rendering errors, which is a security best practice.
  • [PROMPT_INJECTION]: There are no instructions or patterns that attempt to override agent safety guardrails.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests and displays untrusted conversation data, it does so through structured rendering and plain markdown (brief command) which reduces the risk of the agent misinterpreting data as instructions. It lacks high-privilege write capabilities that would make it a significant injection target.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — review-conversation