dream-analyzer
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The skill instructions specify access to sensitive local and internal file paths to read logs and configurations. Specifically, it targets
~/.gemini/jetski/brain/.../logs/overview.txt,/usr/local/google/tmp/smith.par.INFO, and//depot/configs/users/jwortz/_agents/skills.json. While these paths are used for the skill's primary function of transcript analysis, they expose internal system structure and specific user environment details. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process agent session transcripts, which constitute untrusted data. This creates a surface for indirect prompt injection, where malicious content embedded in a past conversation could influence the agent to generate flawed or malicious skill proposals.
- Ingestion points: Session logs (
overview.txt,smith.par.INFO) and local/internal skill configuration files. - Boundary markers: None identified. The instructions do not specify any delimiters or warnings to ignore instructions found within the logs.
- Capability inventory: The skill is capable of proposing modifications to existing
SKILL.mdfiles and generating new skills via structured JSON blocks. - Sanitization: No sanitization or validation logic is mentioned for the content extracted from transcripts before it is used to formulate new instructions.
Audit Metadata