arize-instrumentation
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches instrumentation libraries and utilities from official repositories and package registries. These downloads are considered safe as they target a well-known service provider.
- [REMOTE_CODE_EXECUTION]: Includes instructions for running the Arize Tracing Assistant via
uvx, which is a vendor-provided utility for instrumentation assistance within IDEs. - [COMMAND_EXECUTION]: Utilizes the
axCLI for authenticated profile management and trace verification tasks. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes application source code and environment configurations, presenting a theoretical injection surface. Ingestion points: reads manifests and .env files during Phase 1. Capability inventory: performs package installation, file modification, and CLI execution. Boundaries and sanitization: not explicitly specified.
Audit Metadata