sota-observability

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from a codebase being audited, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: The skill instructs the agent to read and search files within directories such as src/, k8s/, deploy/, and charts/ using command-line tools like grep and find (detailed in rules/06-audit-playbook.md).\n
  • Boundary markers: There are no explicit instructions for the agent to use boundary markers or to ignore instructions that may be embedded within the audited files.\n
  • Capability inventory: The skill utilizes the agent's capability to execute shell commands and read file system content to evaluate the observability posture of a system.\n
  • Sanitization: The skill does not provide mechanisms for sanitizing or escaping the untrusted data read from the codebase before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:37 AM
Security Audit — agent-trust-hub — sota-observability