exploring-replay-vision-observations
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill describes standard operational procedures for using PostHog's Replay Vision API. It does not contain any malicious patterns such as remote code execution, unauthorized network access, or persistence mechanisms. All referenced tools (e.g., vision-scanners-list, vision-scanners-get) and URL structures are consistent with PostHog's platform services.
- [PROMPT_INJECTION]: The skill processes untrusted data from scanner results, representing a surface for indirect prompt injection. 1. Ingestion points: Data enters the context via observations retrieved through tools like
vision-scanners-observations-get. 2. Boundary markers: The skill does not specify explicit boundary markers for the data ingestion. 3. Capability inventory: The skill uses tools to list and retrieve findings and trigger on-demand scans, while instructing the agent to summarize patterns and create insights or playlists. 4. Sanitization: To mitigate injection risks, the instructions mandate that the agent must 'corroborate before you act' and verify findings against raw session recordings.
Audit Metadata