session-analyst

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches conversation transcripts from signed URLs provided by the vendor API. This is a functional requirement for generating coaching reports.
  • [DATA_EXFILTRATION]: The skill handles sensitive data including user emails and session transcripts. While intended for report generation and distribution via connected tools (e.g., email or slides), this creates an exposure surface for individual performance and contact data.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted transcript content and API-provided text fields without explicit sanitization or delimiters.
  • Ingestion points: Transcripts retrieved via transcript_url and text fields from the session data objects.
  • Boundary markers: Absent; there are no instructions to the agent to distinguish between its own logic and potentially malicious instructions embedded in the transcripts.
  • Capability inventory: The skill can read organization data and send formatted content to external tools. It does not have access to shell execution or system-level modification tools.
  • Sanitization: No sanitization or validation of external content is described before the data is aggregated into reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 06:37 PM
Security Audit — agent-trust-hub — session-analyst