cargo-observability
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines alerts that ingest data from external telemetry and database sources and interpolate it into action configurations.\n
- Ingestion points: Results from
orchestrationQueryandstorageQuery, and telemetry fields such asexecutionTitleOrErrorMessagedefined inSKILL.mdandreferences/scopes-and-thresholds.md.\n - Boundary markers: Absent. The templating system described in
references/alert-lifecycle.md(e.g.,{{event.value}}) does not implement visible delimiters or instructions to ignore embedded commands.\n - Capability inventory: Alerts can trigger
agent,connector,tool, andnativeactions as described inSKILL.mdandreferences/alert-lifecycle.md.\n - Sanitization: No documented evidence of sanitization or escaping of measured values before they are passed to automated actions.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@cargo-ai/clipackage from the npm registry to provide the command-line interface required for observability operations.
Audit Metadata