monitoring-tempo
Warn
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
tempo_searchfunction inSKILL.mdexecutes a Python snippet usingpython3 -c. This snippet interpolates the${traceql}shell variable directly into a Python string literal. This pattern is vulnerable to command injection if the variable contains unescaped single quotes or other shell-sensitive characters, allowing an attacker to execute arbitrary Python code. - [COMMAND_EXECUTION]: The skill relies on local shell execution for its core functionality, using
bash,curl, andjqto query the Tempo API and process the resulting JSON data. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto make network requests to the Tempo API endpoint defined by theTEMPO_BASE_URLenvironment variable. While this is necessary for the skill's functionality, it represents outbound network activity. - [PROMPT_INJECTION]: The skill processes distributed tracing data from the Tempo API. If the tracing data (such as span attributes or service names) contains malicious instructions, they could potentially influence the agent's behavior during subsequent processing steps, representing an indirect prompt injection surface.
Audit Metadata