signals-scout-replay-vision

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill instructions focus on valid analytical tasks using established PostHog tools. Analysis of the 10 threat categories, including prompt injection, data exfiltration, and obfuscation, yielded no findings.
  • [SAFE]: While the skill processes untrusted user-generated content from scanner outputs, it incorporates robust defensive instructions. It explicitly mandates that the agent treat all scanner output as data snippets rather than instructions, effectively addressing the risk of indirect prompt injection at the prompt level. Ingestion points include the scanner_output_* properties in SKILL.md. Boundary markers and explicit sanitization logic are present in the 'Untrusted data' section. Capabilities are limited to reporting and SQL-based analytics.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 12:28 PM
Security Audit — agent-trust-hub — signals-scout-replay-vision