observability-engineering

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides setup instructions for MCP servers using environment variables for sensitive tokens (e.g., $DD_API_KEY, $GITHUB_PERSONAL_ACCESS_TOKEN). This follows standard security best practices for secret management by avoiding hardcoded credentials.- [EXTERNAL_DOWNLOADS]: Guidance is provided for running and installing MCP servers through standard package runners like uvx and npx. The referenced repositories and services (Datadog, Grafana, Prometheus, GitHub) are well-known and reputable within the technology community.- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to analyze external telemetry (logs, metrics, traces), it defines an ingestion surface for external data. However, the skill acts solely as an analytical framework and lacks any internal executable scripts or tools that could be exploited through the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 04:05 AM