observability-designer
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions in SKILL.md and documentation do not contain any patterns attempting to override agent behavior or bypass safety guardrails.
- [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The scripts read local configuration files and write outputs to user-specified paths without performing network operations to external domains.
- [REMOTE_CODE_EXECUTION]: The skill does not perform remote script execution or download untrusted packages. The README correctly states that the scripts utilize the Python standard library only.
- [INDIRECT_PROMPT_INJECTION]: While the scripts ingest external data (JSON service definitions and alert configurations), the skill lacks dangerous capabilities such as network requests, command execution (subprocess), or dynamic code evaluation (eval/exec) that could be exploited via malicious input data.
- [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file does not utilize any dynamic shell execution patterns (!
command) that could be triggered during skill loading. - [OBFUSCATION]: No obfuscated strings, hidden URLs, or malicious homoglyph patterns were detected in the source code or documentation.
Audit Metadata