investigating-replay

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an inherent surface for indirect prompt injection due to its core function of processing untrusted event and session data. This is an expected and managed risk for diagnostic tools.
  • Ingestion points: Event properties (e.g., $exception_message), person properties, and session metadata retrieved via posthog:execute-sql, posthog:persons-retrieve, and posthog:session-recording-get.
  • Boundary markers: No explicit delimiters or boundary instructions are defined in the workflow.
  • Capability inventory: The agent has the ability to execute SQL queries and search error tracking issues via the provided tools.
  • Sanitization: No data sanitization logic is specified in the skill instructions.
  • [SAFE]: All operations utilize the official posthog: toolset, and the workflow is consistent with the intended primary use-case of session investigation by the vendor.
  • [SAFE]: No signs of obfuscation, hardcoded credentials, or unauthorized network operations were detected in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 12:53 PM
Security Audit — agent-trust-hub — investigating-replay