creating-replay-vision-scanners

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of automated scanners that process untrusted session recording data (events, URLs, and properties) via LLM prompts.
  • Ingestion points: The query field in vision-scanners-create and vision-scanners-update selects session recordings from external user interactions for analysis.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when incorporating session data into the scanner_config prompts.
  • Capability inventory: The skill utilizes tools to create and update automated scanners (vision-scanners-create, vision-scanners-update) that generate queryable observation events.
  • Sanitization: There are no instructions for sanitizing or filtering session data before it is processed by the scanner's LLM model.
  • [SAFE]: The skill belongs to the official 'posthog' vendor and interacts exclusively with legitimate PostHog infrastructure and tools. It includes comprehensive guidance on avoiding accidental budget exhaustion through mandatory cost estimation checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 03:59 PM
Security Audit — agent-trust-hub — creating-replay-vision-scanners