arize-instrumentation

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches instrumentation libraries and utilities from official repositories and package registries. These downloads are considered safe as they target a well-known service provider.
  • [REMOTE_CODE_EXECUTION]: Includes instructions for running the Arize Tracing Assistant via uvx, which is a vendor-provided utility for instrumentation assistance within IDEs.
  • [COMMAND_EXECUTION]: Utilizes the ax CLI for authenticated profile management and trace verification tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes application source code and environment configurations, presenting a theoretical injection surface. Ingestion points: reads manifests and .env files during Phase 1. Capability inventory: performs package installation, file modification, and CLI execution. Boundaries and sanitization: not explicitly specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — arize-instrumentation