observability-designer

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md and documentation do not contain any patterns attempting to override agent behavior or bypass safety guardrails.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The scripts read local configuration files and write outputs to user-specified paths without performing network operations to external domains.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform remote script execution or download untrusted packages. The README correctly states that the scripts utilize the Python standard library only.
  • [INDIRECT_PROMPT_INJECTION]: While the scripts ingest external data (JSON service definitions and alert configurations), the skill lacks dangerous capabilities such as network requests, command execution (subprocess), or dynamic code evaluation (eval/exec) that could be exploited via malicious input data.
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file does not utilize any dynamic shell execution patterns (!command) that could be triggered during skill loading.
  • [OBFUSCATION]: No obfuscated strings, hidden URLs, or malicious homoglyph patterns were detected in the source code or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 11:13 AM
Security Audit — agent-trust-hub — observability-designer