o11y-logging
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a shell script
scripts/otel-smoke.shand uses thejoelclawCLI tool to verify telemetry delivery. These commands are standard for development workflows and are used to probe local services or specific infrastructure defined by environment variables. - [EXTERNAL_DOWNLOADS]: The verification script performs network requests using
curlto send observability events to a worker endpoint. By default, this targetslocalhost, and the script usesjqto safely construct the JSON payloads from user-provided arguments. - [INDIRECT_PROMPT_INJECTION]: The skill handles high-cardinality data via
metadatafields in events. While external data processed by logging systems can be a surface for indirect injection, the provided implementation uses structured JSON encoding (viajq) to ensure that input data is treated as data rather than instructions.
Audit Metadata