logging-observability

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it ingests untrusted data in the form of service and stack descriptions.
  • Ingestion points: Service descriptions and stack information provided via argument-hint in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: The skill has access to Read, Write, Edit, and Bash (restricted to npm, npx, pip, and docker) as defined in SKILL.md.
  • Sanitization: The instructions do not explicitly mandate sanitization of the user input before it is used to generate configuration files or execute commands.
  • [SAFE]: The skill proactively addresses security by teaching the 'Anti-Pattern 1: Logging PII or Secrets in Production' and provides code examples for structural redaction of sensitive fields (e.g., authorization, password, cardNumber, ssn) using industry-standard tools like Pino and Winston.
  • [SAFE]: All identified dependencies for Node.js, Python, and Go are official, well-known OpenTelemetry and observability packages from established registries (NPM, PyPI, and GitHub).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — logging-observability