observability

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing standard OpenTelemetry packages from official registries (NPM and PyPI). These include well-known libraries such as @opentelemetry/api, @opentelemetry/auto-instrumentations-node, and opentelemetry-distro for service instrumentation.
  • [COMMAND_EXECUTION]: Includes a shell script (scripts/verify.sh) designed to lint and validate OpenTelemetry configurations. The script performs local read-only operations using standard Unix tools like grep, find, and awk to verify that exporters are correctly wired and that service names are defined. It does not perform any network operations or administrative tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user requirements for service instrumentation and output observability configurations. It mitigates potential risks by providing structured recipes and recommending explicit boundaries, such as the use of an OTel Collector for redacting sensitive data before it is exported to external backends.
  • [CREDENTIALS_SAFE]: The skill demonstrates secure credential management by using environment variable interpolation (e.g., ${env:HONEYCOMB_API_KEY}) in configuration files rather than hardcoding sensitive tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:10 PM
Security Audit — agent-trust-hub — observability