setup-tracing
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads OpenAPI documentation from the vendor's official domain (api.coval.dev) to verify API structures.
- [COMMAND_EXECUTION]: Utilizes the vendor's CLI tool (coval) and standard developer tools (npm, python, go) to perform environment discovery and verify the implementation.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface. Ingestion points: Customer repository files, public Coval documentation, and remote OpenAPI specifications. Boundary markers: Absent. Capability inventory: Execution of shell commands and file system writes. Sanitization: Includes a directive to redact sensitive metadata from API responses to prevent credential exposure.
- [SAFE]: The skill implements security-conscious practices, such as explicitly forbidding the storage or printing of API keys and recommending the use of environment variables for secrets.
Audit Metadata