nemo-relay-plugin-observability
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides robust guidance on secure credential management, explicitly instructing users to map authentication headers to environment variables (e.g.,
header_env) rather than hardcoding secrets in configuration files or code. - [SAFE]: The skill includes mandatory instructions for data sanitization and redaction, requiring that exporters be verified with synthetic, non-sensitive payloads before processing production data to prevent sensitive information leakage.
- [SAFE]: The documentation includes security-focused validation checklists for all export types (ATOF, ATIF, OpenTelemetry, OpenInference), covering endpoint verification, TLS certificate requirements, and the redaction of diagnostic output.
- [SAFE]: The skill targets well-known, established observability services (such as Jaeger, Arize Phoenix, Honeycomb, and Grafana Tempo) and provides safe configuration examples using local loopback endpoints for initial testing.
Audit Metadata