log-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and analyze external application logs, which are untrusted data sources that could be influenced by attackers. If an attacker can inject malicious text into the logs, they might influence the agent's behavior during analysis.\n
- Ingestion points: Processes log files provided as input (e.g., app.log in SKILL.md).\n
- Boundary markers: The skill lack specific delimiters or instructions to the agent to disregard potential instructions embedded within the logs themselves.\n
- Capability inventory: Suggests the use of shell commands like grep and awk to process the data (SKILL.md).\n
- Sanitization: No sanitization or validation of the log content is described before processing.\n- [COMMAND_EXECUTION]: The skill provides specific bash command patterns for the agent to use when analyzing logs on the local system.\n
- Evidence: Shell command examples using grep, awk, cut, sort, and uniq are provided in the 'Analysis Techniques' section of SKILL.md.
Audit Metadata