sota-observability

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown files and rules for software engineering. No malicious scripts, prompt injections, or unauthorized data access patterns were identified in the content.
  • [SAFE]: The audit playbook in rules/06-audit-playbook.md provides shell command examples using standard utilities like grep and find. These are intended for static analysis of target codebases to improve reliability and security, and do not involve remote code execution or data exfiltration.
  • [SAFE]: The skill explicitly advocates for security best practices, including the central redaction of PII and secrets in telemetry pipelines and the protection of internal diagnostic endpoints (e.g., pprof, actuators) from public access.
  • [SAFE]: The external resources referenced (OpenTelemetry, Prometheus, Grafana, Sentry) are well-known, industry-standard observability tools. References to these services are informational and represent legitimate engineering workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-observability