trace

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze session logs, event streams, and behavioral data which could potentially contain malicious instructions embedded within metadata or custom event properties.\n
  • Ingestion points: External session recordings and user logs provided at runtime (SKILL.md, reference/session-analysis.md).\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the analyzed data streams, though it does enforce privacy boundaries.\n
  • Capability inventory: The skill is primarily analytical, but it generates reports and triggers handoffs to other agents (e.g., Palette, Echo) which could be influenced by poisoned data.\n
  • Sanitization: The skill mandates PII masking and client-side redaction, which mitigates exposure risks but is not specifically designed to filter adversarial natural language instructions.\n- [SAFE]: The skill exhibits an exceptionally strong security posture regarding data privacy and legal compliance.\n
  • It includes explicit prohibitions against exposing PII, recording without consent, and transmitting unredacted payloads.\n
  • Detailed references are provided for GDPR Articles 5-6, CCPA, and emerging 2026 legal standards like the EU Digital Omnibus Package.\n
  • No hardcoded credentials, suspicious network calls, or obfuscated code were detected across the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — trace