session-analyst

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted transcript data.
  • Ingestion points: The skill fetches session data and conversation text from signed URLs (transcript_url) provided by the ttai:list_sessions and ttai:get_sessions_batch tools, as described in SKILL.md.
  • Boundary markers: There are no specific instructions or delimiters defined to isolate the transcript content from the agent's internal instructions when generating reports.
  • Capability inventory: The skill has the ability to hand off processed data to other connected MCP tools such as slides, email, and docs for distribution, creating a potential path for injected instructions to reach downstream applications.
  • Sanitization: The skill lacks explicit instructions for sanitizing, escaping, or filtering the content of the transcripts before they are interpolated into the coaching and performance report templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 10:52 AM
Security Audit — agent-trust-hub — session-analyst