sota-observability
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown files and rules for software engineering. No malicious scripts, prompt injections, or unauthorized data access patterns were identified in the content.
- [SAFE]: The audit playbook in
rules/06-audit-playbook.mdprovides shell command examples using standard utilities likegrepandfind. These are intended for static analysis of target codebases to improve reliability and security, and do not involve remote code execution or data exfiltration. - [SAFE]: The skill explicitly advocates for security best practices, including the central redaction of PII and secrets in telemetry pipelines and the protection of internal diagnostic endpoints (e.g., pprof, actuators) from public access.
- [SAFE]: The external resources referenced (OpenTelemetry, Prometheus, Grafana, Sentry) are well-known, industry-standard observability tools. References to these services are informational and represent legitimate engineering workflows.
Audit Metadata