opentelemetry-instrumentation
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical documentation and advisory tool for OpenTelemetry SDK instrumentation across multiple programming languages (Java, Python, Node.js, .NET, and Go).
- [SAFE]: External references are directed exclusively to official and well-known domains, including
coralogix.com,opentelemetry.io, and verified GitHub organizations such asgithub.com/open-telemetryandgithub.com/coralogix. - [SAFE]: Secret management guidance is robust; the skill consistently instructs users to use placeholders (e.g.,
<CORALOGIX_API_KEY>,<Send-Your-Data key>) and explicitly warns against committing secrets to source control, recommending environment variables or secrets managers instead. - [SAFE]: The package dependencies mentioned, such as
@coralogix/opentelemetryfor Node.js andcoralogix-opentelemetryfor Python, are official vendor-maintained libraries that align with the skill's stated purpose and authorship. - [SAFE]: No evidence of prompt injection, obfuscation (such as Base64 or zero-width characters), or unauthorized network operations was found in the instructions, reference materials, or evaluation files.
- [SAFE]: Dynamic context injection patterns (e.g., shell commands executed at load time) are not present in the skill files.
Audit Metadata