arize-ai-provider-integration

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests data from the Arize platform that could influence subsequent actions. Ingestion points: Untrusted data enters the agent context via the output of ax ai-integrations list and ax ai-integrations get commands as referenced in SKILL.md. Boundary markers: The instructions lack specific delimiters or instructions to ignore potential commands embedded within the retrieved data. Capability inventory: The skill has the capability to execute shell commands (ax CLI) to modify resources (create, update, delete) as described in SKILL.md. Sanitization: There is no evidence of sanitization or validation of the external content before it is used in subsequent CLI operations.
  • [COMMAND_EXECUTION]: The skill's primary function involves executing shell commands through the ax CLI. This provides a capability to interact with the Arize environment and manage integration credentials.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the arize-ax-cli package from standard registries (e.g., via pip or uv). This is a dependency on a well-known service required for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — arize-ai-provider-integration