anonymize-logs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted customer-provided logs (ingested via @-mention or inline paste as described in SKILL.md). It addresses potential injection risks by providing specific instructions to detect and neutralize probe patterns like ${jndi: (Log4Shell style), replacing the entire field with a synthetic value. It employs a two-pass mapping system to ensure consistency and integrity across the sanitized output without reformatting content.
  • [COMMAND_EXECUTION]: The instructions include a local Python one-liner intended for the agent to validate the structural integrity of processed NDJSON files. The command is static, runs locally, and does not interpolate untrusted data into the shell execution context, serving as a functional safety check for the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:03 PM
Security Audit — agent-trust-hub — anonymize-logs