observe-it
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions require the agent to access highly sensitive project configuration files to discover the project's existing observability stack.\n
- Evidence: Step 2 of the workflow in SKILL.md directs the agent to "Read docs, .env* names, SDK imports, dashboards, alert rules". Environment files (matching .env*) are high-sensitivity assets that commonly contain secrets, API keys, and private credentials. Accessing these files is a high-risk operation that could lead to accidental credential exposure.\n- [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data and possesses file-system modification capabilities, creating a potential vector for indirect prompt injection.\n
- Ingestion points: The skill accepts user-provided arguments for "path|route|job|feature" to be instrumented.\n
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands when the agent reads external documentation or project files.\n
- Capability inventory: The agent can read project documentation and configuration and can write new instrumentation code (logs, traces, metrics) into the codebase.\n
- Sanitization: While the skill includes high-level guardrails against logging PII and secrets, it does not specify technical validation or escaping for the user-provided strings used in the instrumentation process.\n- Remediation Guidance:\n
- Instruct the agent to check for the presence of specific environment variable names rather than reading the entire content of .env files.\n
- Require human review for all code modifications performed by the agent.\n
- Ensure that all instrumentation data is properly sanitized before being passed to observability backends.
Audit Metadata