dream-analyzer

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The skill instructions specify access to sensitive local and internal file paths to read logs and configurations. Specifically, it targets ~/.gemini/jetski/brain/.../logs/overview.txt, /usr/local/google/tmp/smith.par.INFO, and //depot/configs/users/jwortz/_agents/skills.json. While these paths are used for the skill's primary function of transcript analysis, they expose internal system structure and specific user environment details.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process agent session transcripts, which constitute untrusted data. This creates a surface for indirect prompt injection, where malicious content embedded in a past conversation could influence the agent to generate flawed or malicious skill proposals.
  • Ingestion points: Session logs (overview.txt, smith.par.INFO) and local/internal skill configuration files.
  • Boundary markers: None identified. The instructions do not specify any delimiters or warnings to ignore instructions found within the logs.
  • Capability inventory: The skill is capable of proposing modifications to existing SKILL.md files and generating new skills via structured JSON blocks.
  • Sanitization: No sanitization or validation logic is mentioned for the content extracted from transcripts before it is used to formulate new instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — dream-analyzer