exploring-replay-vision-observations
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The skill uses platform-specific tools to manage internal data.
- [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses the risk of indirect prompt injection by identifying that session recordings (which originate from external users) are untrusted input. It provides clear defensive instructions to the agent to treat this data as text only and to disregard any instructions or tool requests found within it.
- [COMMAND_EXECUTION]: All tools referenced (e.g., vision-scanners-list, vision-scanners-get) are standard platform MCP tools used for data retrieval and configuration management within the PostHog environment.
Audit Metadata