braintrust-tracing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's tracing architecture processes prompt data to include metadata tags, creating a surface for indirect prompt injection.
  • Ingestion points: The skill processes tool_input.prompt and [BRAINTRUST_TRACE_CONTEXT] tags during the PreToolUse hook stage.
  • Boundary markers: The architecture employs [BRAINTRUST_TRACE_CONTEXT] and [/BRAINTRUST_TRACE_CONTEXT] delimiters to scope injected metadata.
  • Capability inventory: The skill executes local shell hooks, invokes Python scripts via uv run, and performs network operations with the Braintrust API.
  • Sanitization: There is no documented logic for sanitizing or filtering content within the trace tags before they are processed.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates network communication with Braintrust's official API endpoint at https://api.braintrust.dev to record session data.
  • [COMMAND_EXECUTION]: The skill executes local shell scripts located within the .claude/plugins/braintrust-tracing/hooks/ directory and utilizes the uv tool to run Python analysis scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — braintrust-tracing