llm-obs-eval-bootstrap

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the vendor-provided 'pup' CLI tool via Bash to perform search and retrieval operations within Datadog's LLM Observability platform. This includes operations like searching spans and fetching content, which are standard for the tool's intended purpose.
  • [DATA_EXFILTRATION]: The skill transfers observability data and configuration between the agent context and Datadog's official domains (e.g., mcp.datadoghq.com). This data flow is restricted to the vendor's own infrastructure and is necessary for the skill's function.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests production trace content for analysis to identify evaluation dimensions. While this content originates from external production environments, the skill mitigates risk by requiring explicit user confirmation of all generated evaluators and performing PII anonymization before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:21 PM
Security Audit — agent-trust-hub — llm-obs-eval-bootstrap