google-agents-cli-observability
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- External Documentation References: The skill directs the agent to fetch additional technical documentation from the
adk.devdomain. These resources provide detailed setup instructions for various observability providers and frameworks. - Telemetry and Content Logging: The skill facilitates the capture of prompt and response data for export to Google Cloud Storage and BigQuery. This functionality is intended for auditing and debugging AI interactions. Users should ensure that the configured logging levels align with their data sensitivity policies.
- Infrastructure Provisioning: The instructions include Terraform configurations and shell commands for creating cloud resources such as logging sinks and BigQuery datasets. These operations are part of the standard deployment workflow and require appropriate identity and access management (IAM) permissions.
- Indirect Prompt Injection Surface: The skill defines a mechanism for collecting end-user feedback via a FastAPI endpoint in
references/feedback-mechanism.md. - Ingestion points: Data enters the system through a
FeedbackPydantic model at the/feedbackendpoint inreferences/feedback-mechanism.md. - Boundary markers: The prompt does not specify delimiters for the free-text feedback field.
- Capability inventory: The ingested data is logged using the
google-cloud-logginglibrary, which routes data to Cloud Logging and BigQuery via a log sink. - Sanitization: The documentation provides a note advising developers to implement PII redaction or data retention policies for user-submitted text.
Audit Metadata