observability

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references tool versions and official documentation from trusted organizations and well-known services, including GitHub repositories for Prometheus, OpenTelemetry, and Grafana. These references are used solely for version pinning and documentation purposes.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard observability CLI tools (promtool, otelcol, amtool, jq) for local validation of generated configuration files. This is a standard and safe practice for ensuring the correctness of metrics and tracing pipelines.
  • [DATA_EXFILTRATION]: The skill contains explicit rules and an 'AI Self-Check' to prevent the inclusion of secrets, PII, or authentication headers in telemetry data (metrics, logs, and traces).
  • [INDIRECT_PROMPT_INJECTION]: As an auditing tool, the skill is designed to ingest and analyze repository content (configurations and source code). While this presents a theoretical surface for indirect prompt injection, the risk is mitigated by the skill's requirement to use specialized parsers and validation tools to verify all findings and generated artifacts.
  • [DYNAMIC_EXECUTION]: The skill generates structured configuration files (YAML, JSON) for observability stacks. This generation follows predefined templates and is subject to mandatory validation steps before being presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 05:33 PM
Security Audit — agent-trust-hub — observability