creating-replay-vision-scanners
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of automated scanners that process untrusted session recording data (events, URLs, and properties) via LLM prompts.
- Ingestion points: The
queryfield invision-scanners-createandvision-scanners-updateselects session recordings from external user interactions for analysis. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when incorporating session data into the
scanner_configprompts. - Capability inventory: The skill utilizes tools to create and update automated scanners (
vision-scanners-create,vision-scanners-update) that generate queryable observation events. - Sanitization: There are no instructions for sanitizing or filtering session data before it is processed by the scanner's LLM model.
- [SAFE]: The skill belongs to the official 'posthog' vendor and interacts exclusively with legitimate PostHog infrastructure and tools. It includes comprehensive guidance on avoiding accidental budget exhaustion through mandatory cost estimation checks.
Audit Metadata