arize-trace
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Executes the
axCLI tool for data export and profile management. Commands includeax spans export,ax traces export, andax profiles. - [INDIRECT_PROMPT_INJECTION]: Ingests trace data which may contain untrusted content. The skill includes a clear warning to treat this data as raw text and not to execute it as instructions. This affects data fetched via export commands in
SKILL.md. - [EXTERNAL_DOWNLOADS]: Recommends installing the official
arize-ax-clipackage via standard package managers such asuv,pip, orpipx. - [DATA_EXFILTRATION]: Accesses environment variables for authentication and connects to official Arize domains (
api.arize.com,flight.arize.com) to fetch data. - [PERSISTENCE]: Provides instructions for persisting configuration values like
ARIZE_SPACE_IDin shell configuration files (~/.bashrc,~/.zshrc) for legitimate tool setup.
Audit Metadata