span-convention-review
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
git diffto identify changes in the source code. This is a standard and expected operation for a code review tool. - [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from official and trusted sources, including Sentry's developer documentation (
develop.sentry.dev) and OpenTelemetry's specification site (opentelemetry.io), to perform its analysis. These are well-known, authoritative domains for this context. - [DATA_EXFILTRATION]: No exfiltration patterns were found. In fact, the skill includes a specific security-positive step (Step 4e) to check for and flag the accidental leakage of sensitive data (PII, database credentials, or unredacted URLs) in tracing spans.
- [PROMPT_INJECTION]: The instructions are clearly defined and focused on the review task without attempting to bypass safety filters or override system behaviors.
Audit Metadata