runlens
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions include methods to install the
runlensCLI tool, such as using Homebrew (brew install itamaker/tap/runlens) or downloading binaries from the author's GitHub repository (github.com/itamaker/runlens-skill). These resources are hosted on the author's official channels and represent standard installation procedures for developer tools. - [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted external data in the form of JSONL trace files via the
-inputflag. - Ingestion points: The
runlens summaryandrunlens diagnosecommands read user-provided file paths. - Boundary markers: The tool expects structured JSONL formatting, which provides implicit structural separation between data entries.
- Capability inventory: The tool's capabilities are limited to statistical aggregation (latency calculations, failure rates, and token counts) and identifying patterns in logs. It does not execute commands based on the log content.
- Sanitization: The skill documentation specifies robust error handling for malformed JSON lines, providing line numbers for correction.
Audit Metadata