skills/simota/agent-skills/trace/Gen Agent Trust Hub

trace

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference files focus entirely on UX research, session analysis methodologies, and privacy best practices. No malicious code or injection attempts were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external data (session recordings, user event logs). While this presents an inherent surface for indirect prompt injection, the skill includes explicit guardrails requiring PII masking, client-side redaction, and human verification of all AI-generated summaries before reporting, effectively mitigating the risk.
  • [DATA_EXFILTRATION]: The skill provides detailed guidance on maintaining user privacy, including the use of Global Privacy Control (GPC) signals and whitelisting non-sensitive fields. It explicitly warns against transmitting unredacted payloads to third-party vendors to avoid wiretapping claims (CIPA) and GDPR violations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — trace