opentelemetry-instrumentation

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical documentation and advisory tool for OpenTelemetry SDK instrumentation across multiple programming languages (Java, Python, Node.js, .NET, and Go).
  • [SAFE]: External references are directed exclusively to official and well-known domains, including coralogix.com, opentelemetry.io, and verified GitHub organizations such as github.com/open-telemetry and github.com/coralogix.
  • [SAFE]: Secret management guidance is robust; the skill consistently instructs users to use placeholders (e.g., <CORALOGIX_API_KEY>, <Send-Your-Data key>) and explicitly warns against committing secrets to source control, recommending environment variables or secrets managers instead.
  • [SAFE]: The package dependencies mentioned, such as @coralogix/opentelemetry for Node.js and coralogix-opentelemetry for Python, are official vendor-maintained libraries that align with the skill's stated purpose and authorship.
  • [SAFE]: No evidence of prompt injection, obfuscation (such as Base64 or zero-width characters), or unauthorized network operations was found in the instructions, reference materials, or evaluation files.
  • [SAFE]: Dynamic context injection patterns (e.g., shell commands executed at load time) are not present in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:36 AM