observability-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a reference guide for observability best practices, containing standard configuration files for Prometheus and Loki, and boilerplate code for OpenTelemetry and FastAPI.
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for metrics middleware and health check endpoints that ingest untrusted data (such as HTTP request paths, methods, and status codes).
- Ingestion points: Request metadata is captured in
metrics_middlewareand readiness checks inSKILL.md. - Boundary markers: None specific to the prompt, as this is application code logic.
- Capability inventory: The skill only performs standard logging, metric incrementing, and trace span creation; it does not contain subprocess calls, network exfiltration, or file system write operations.
- Sanitization: Standard library usage for logging and metrics typically handles serialization safely.
Audit Metadata