investigating-logs

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze log data which originates from external services. This creates an attack surface for indirect prompt injection where malicious instructions embedded in logs could attempt to influence the agent's behavior during investigation. \n- Ingestion points: posthog:query-logs, posthog:logs-patterns, posthog:logs-patterns-diff, and posthog:logs-facet-values-create all retrieve and process untrusted log data. \n- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' wrappers when the agent processes or outputs log content. \n- Capability inventory: The skill utilizes a set of PostHog-specific MCP tools. It does not include tools for arbitrary shell execution, file system writes, or network requests outside the PostHog environment. \n- Sanitization: There is no mention of sanitizing or escaping the log data before it is presented to or processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:39 AM
Security Audit — agent-trust-hub — investigating-logs