update-otel-genai-conventions

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Data Ingestion Surface]: The skill is designed to analyze external data such as pull request descriptions and changelog fragments from the OpenTelemetry project. This process involves ingestion points (identified in SKILL.md and references/change-classification.md) that represent a potential area to review for indirect prompt injection. The skill currently lacks explicit boundary markers or sanitization for this external text; however, its capability inventory is limited to local file modifications and development script execution, all of which are managed through a structured planning process that facilitates human review.
  • [Development Workflow Commands]: To verify implementation changes, the skill references standard repository-local scripts such as build.sh and dotnet test. These commands are part of the intended development workflow and are used to ensure the reliability of convention updates within the codebase.
  • [External Resource Integration]: The skill maintains alignment with industry standards by referencing specifications from well-known repositories, specifically those of the OpenTelemetry project. These references are documented as they are the authoritative source for the conventions the skill is designed to implement.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:31 AM
Security Audit — agent-trust-hub — update-otel-genai-conventions