observability

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, prompt injections, or unauthorized data exfiltration techniques were detected.
  • [DATA_EXFILTRATION]: The skill provides defensive guidance for redacting sensitive information from logs. It includes a SECRET_PATTERNS regex to detect and mask common credentials like Bearer tokens, OpenAI keys (sk-), Slack tokens (xox-), and Telegram bot tokens. This is a security best practice for observability tools.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override agent behavior or bypass safety filters.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or unverifiable dependency installations were found. The code snippets provided are for internal application logic (Effect, Schema, OpenTelemetry).
  • [EXTERNAL_DOWNLOADS]: The skill mentions standard OpenTelemetry endpoints and cited sources (e.g., Stripe, Boris Tane's blog) for educational purposes, which does not constitute a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:19 AM
Security Audit — agent-trust-hub — observability