cx-service-catalog

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively uses cx service-catalog commands which are documented as read-only diagnostic tools for application performance monitoring (APM) data. All external resources belong to the vendor's own infrastructure.
  • [COMMAND_EXECUTION]: The skill uses the cx CLI tool, which is the expected interface for the vendor. The commands are scoped to querying metadata (schema, entity types) and aggregated telemetry data.
  • [DATA_EXPOSURE]: The skill accesses observability data (latency, error rates, resource usage) which is the intended purpose for an APM skill. It does not attempt to access sensitive local files or environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from the Service Catalog API. While it ingests external data, it uses clear boundaries and discovery commands (schema, entity-types) to validate inputs before querying, reducing the risk of schema confusion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 09:28 AM
Security Audit — agent-trust-hub — cx-service-catalog