phoenix-observability

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an evaluation framework that processes untrusted trace data from LLM applications, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Trace data and spans are ingested from the Phoenix server using client.get_spans_dataframe() as shown in SKILL.md and references/advanced-usage.md.
  • Boundary markers: The LLM evaluator templates (e.g., CUSTOM_EVAL_TEMPLATE in references/advanced-usage.md) interpolate variables like {input} and {output} directly into the prompt without utilizing delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill utilizes llm_classify and run_evals (in SKILL.md and references/advanced-usage.md) to execute automated evaluations using LLMs, which can be influenced by the content of the processed traces.
  • Sanitization: No sanitization, escaping, or filtering of the external trace data is implemented before it is passed to the LLM evaluators.
  • [COMMAND_EXECUTION]: The skill provides instructions for managing and deploying the Phoenix observability server using command-line tools.
  • Evidence: The skill documents the use of phoenix serve for launching the server and psql for database verification in SKILL.md and references/troubleshooting.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — phoenix-observability