braintrust-analyze

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script scripts/braintrust_analyze.py using the uv package manager to perform data analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session traces and tool execution logs which are ingested from the Braintrust API. This represents an attack surface where malicious content within the analyzed logs could attempt to influence the agent's summary or analysis.
  • Ingestion points: Data is fetched via the Braintrust API and processed by scripts/braintrust_analyze.py (SKILL.md, SKILL.v6.md).
  • Boundary markers: The instructions do not specify explicit delimiters for the ingested trace data.
  • Capability inventory: The skill uses the Bash tool to run the analysis script. The policy file SKILL.v6.md explicitly forbids Write and Edit actions to mitigate risk.
  • Sanitization: There are no explicit sanitization or filtering steps defined in the skill instructions for the external API data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — braintrust-analyze