observability-and-instrumentation
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill outlines industry-standard best practices for instrumentation and observability. It focuses on structured logging, metric collection (RED/USE patterns), and distributed tracing using OpenTelemetry.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The documentation includes explicit security instructions to never log secrets, tokens, passwords, or PII. It recommends using allowlists for fields rather than logging entire request bodies to prevent data leaks into telemetry pipelines.
- [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted industry libraries such as
@opentelemetry/sdk-node,@opentelemetry/auto-instrumentations-node, andprom-client. These are standard tools for observability and their inclusion aligns with the skill's stated purpose. - [COMMAND_EXECUTION]: Code examples provided are illustrative for application logic (e.g., Express.js middleware and OpenTelemetry SDK initialization) and do not contain any dangerous system command execution patterns.
Audit Metadata