o11y-logging

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell script scripts/otel-smoke.sh and uses the joelclaw CLI tool to verify telemetry delivery. These commands are standard for development workflows and are used to probe local services or specific infrastructure defined by environment variables.
  • [EXTERNAL_DOWNLOADS]: The verification script performs network requests using curl to send observability events to a worker endpoint. By default, this targets localhost, and the script uses jq to safely construct the JSON payloads from user-provided arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles high-cardinality data via metadata fields in events. While external data processed by logging systems can be a surface for indirect injection, the provided implementation uses structured JSON encoding (via jq) to ensure that input data is treated as data rather than instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — o11y-logging