span-convention-review

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git diff to identify changes in the source code. This is a standard and expected operation for a code review tool.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from official and trusted sources, including Sentry's developer documentation (develop.sentry.dev) and OpenTelemetry's specification site (opentelemetry.io), to perform its analysis. These are well-known, authoritative domains for this context.
  • [DATA_EXFILTRATION]: No exfiltration patterns were found. In fact, the skill includes a specific security-positive step (Step 4e) to check for and flag the accidental leakage of sensitive data (PII, database credentials, or unredacted URLs) in tracing spans.
  • [PROMPT_INJECTION]: The instructions are clearly defined and focused on the review task without attempting to bypass safety filters or override system behaviors.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 07:57 PM