cargo-observability

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines alerts that ingest data from external telemetry and database sources and interpolate it into action configurations.\n
  • Ingestion points: Results from orchestrationQuery and storageQuery, and telemetry fields such as executionTitleOrErrorMessage defined in SKILL.md and references/scopes-and-thresholds.md.\n
  • Boundary markers: Absent. The templating system described in references/alert-lifecycle.md (e.g., {{event.value}}) does not implement visible delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: Alerts can trigger agent, connector, tool, and native actions as described in SKILL.md and references/alert-lifecycle.md.\n
  • Sanitization: No documented evidence of sanitization or escaping of measured values before they are passed to automated actions.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @cargo-ai/cli package from the npm registry to provide the command-line interface required for observability operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:36 AM
Security Audit — agent-trust-hub — cargo-observability