monitoring-tempo

Warn

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The tempo_search function in SKILL.md executes a Python snippet using python3 -c. This snippet interpolates the ${traceql} shell variable directly into a Python string literal. This pattern is vulnerable to command injection if the variable contains unescaped single quotes or other shell-sensitive characters, allowing an attacker to execute arbitrary Python code.
  • [COMMAND_EXECUTION]: The skill relies on local shell execution for its core functionality, using bash, curl, and jq to query the Tempo API and process the resulting JSON data.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to make network requests to the Tempo API endpoint defined by the TEMPO_BASE_URL environment variable. While this is necessary for the skill's functionality, it represents outbound network activity.
  • [PROMPT_INJECTION]: The skill processes distributed tracing data from the Tempo API. If the tracing data (such as span attributes or service names) contains malicious instructions, they could potentially influence the agent's behavior during subsequent processing steps, representing an indirect prompt injection surface.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 02:41 AM
Security Audit — agent-trust-hub — monitoring-tempo