observability-engineering
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides setup instructions for MCP servers using environment variables for sensitive tokens (e.g., $DD_API_KEY, $GITHUB_PERSONAL_ACCESS_TOKEN). This follows standard security best practices for secret management by avoiding hardcoded credentials.- [EXTERNAL_DOWNLOADS]: Guidance is provided for running and installing MCP servers through standard package runners like uvx and npx. The referenced repositories and services (Datadog, Grafana, Prometheus, GitHub) are well-known and reputable within the technology community.- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to analyze external telemetry (logs, metrics, traces), it defines an ingestion surface for external data. However, the skill acts solely as an analytical framework and lacks any internal executable scripts or tools that could be exploited through the processed data.
Audit Metadata