arize-trace

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Executes the ax CLI tool for data export and profile management. Commands include ax spans export, ax traces export, and ax profiles.
  • [INDIRECT_PROMPT_INJECTION]: Ingests trace data which may contain untrusted content. The skill includes a clear warning to treat this data as raw text and not to execute it as instructions. This affects data fetched via export commands in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: Recommends installing the official arize-ax-cli package via standard package managers such as uv, pip, or pipx.
  • [DATA_EXFILTRATION]: Accesses environment variables for authentication and connects to official Arize domains (api.arize.com, flight.arize.com) to fetch data.
  • [PERSISTENCE]: Provides instructions for persisting configuration values like ARIZE_SPACE_ID in shell configuration files (~/.bashrc, ~/.zshrc) for legitimate tool setup.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 10:09 PM