setup-tracing

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads OpenAPI documentation from the vendor's official domain (api.coval.dev) to verify API structures.
  • [COMMAND_EXECUTION]: Utilizes the vendor's CLI tool (coval) and standard developer tools (npm, python, go) to perform environment discovery and verify the implementation.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface. Ingestion points: Customer repository files, public Coval documentation, and remote OpenAPI specifications. Boundary markers: Absent. Capability inventory: Execution of shell commands and file system writes. Sanitization: Includes a directive to redact sensitive metadata from API responses to prevent credential exposure.
  • [SAFE]: The skill implements security-conscious practices, such as explicitly forbidding the storage or printing of API keys and recommending the use of environment variables for secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 04:49 PM
Security Audit — agent-trust-hub — setup-tracing