arize-annotation

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements strong security guidelines by instructing the agent to never read sensitive files like .env or ask users for cleartext secrets. It correctly directs authentication to official CLI profile management and environment variables.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingest and processes annotation data such as labels and notes which are then transmitted to the Arize platform. While this represents a data ingestion surface, it is considered a safe application of the tool's core functionality via the official SDK.\n
  • Ingestion points: The annotations_df object and file inputs for CLI batch commands in SKILL.md.\n
  • Boundary markers: None are defined in the provided implementation examples.\n
  • Capability inventory: Uses ArizeClient and ax CLI for authenticated network operations to the Arize API.\n
  • Sanitization: The skill assumes provided data is schema-compliant and does not demonstrate content-based filtering before API submission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — arize-annotation