production-investigation

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown-based instructional content and reference guides. It does not contain executable scripts, binary files, or automated configuration changes.
  • [COMMAND_EXECUTION]: While the skill instructs the agent to execute specific MCP tools (e.g., run_query, run_bubbleup, get_trace), these are standard interactions for observability agents. No arbitrary shell command execution or unauthorized system access was detected.
  • [DATA_EXFILTRATION]: The skill operates within the context of the user's Honeycomb environment. No patterns indicating the exfiltration of sensitive data to external or untrusted domains were found. All references to data access are aligned with the skill's stated purpose of production investigation.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or other sensitive credentials were found in the skill files. The skill correctly assumes that authentication is handled by the underlying MCP environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data returned from the Honeycomb API (such as span attributes and trace logs). This constitutes a standard data ingestion surface, but the skill does not use this data in a way that triggers unsafe actions or bypasses security boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 10:58 PM
Security Audit — agent-trust-hub — production-investigation