skills/itamaker/skills/runlens/Gen Agent Trust Hub

runlens

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include methods to install the runlens CLI tool, such as using Homebrew (brew install itamaker/tap/runlens) or downloading binaries from the author's GitHub repository (github.com/itamaker/runlens-skill). These resources are hosted on the author's official channels and represent standard installation procedures for developer tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted external data in the form of JSONL trace files via the -input flag.
  • Ingestion points: The runlens summary and runlens diagnose commands read user-provided file paths.
  • Boundary markers: The tool expects structured JSONL formatting, which provides implicit structural separation between data entries.
  • Capability inventory: The tool's capabilities are limited to statistical aggregation (latency calculations, failure rates, and token counts) and identifying patterns in logs. It does not execute commands based on the log content.
  • Sanitization: The skill documentation specifies robust error handling for malformed JSON lines, providing line numbers for correction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — runlens