observability-handbook

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a documentation guide for developers to implement observability. It includes specific warnings against logging sensitive data such as raw emails, tokens, or secret query strings, promoting the use of opaque identifiers and sanitized error reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data via application logs and error reporting mechanisms.
  • Ingestion points: Runtime logs, request headers (e.g., x-request-id), and client-side error boundaries.
  • Boundary markers: Instructions mandate the use of redaction patterns (e.g., req_*** IDs) and sanitized error reporting hooks.
  • Capability inventory: The skill is limited to repo-files access for project configuration and logging utility setup.
  • Sanitization: The instructions explicitly require scrubbing PII and server-side stack traces before transmitting data to client reporters or external APM services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:02 AM
Security Audit — agent-trust-hub — observability-handbook