otel-span-events-to-logs-migration

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves a clear technical purpose, assisting developers with a standard refactoring task related to OpenTelemetry instrumentation. It contains no hidden or malicious instructions.
  • [COMMAND_EXECUTION]: Includes a utility script scripts/scan-span-events.sh that uses grep to perform local searches for specific API patterns (e.g., AddEvent, RecordException). This is a benign diagnostic function that does not utilize network access or elevate privileges.
  • [EXTERNAL_DOWNLOADS]: References official OpenTelemetry documentation, specifications, and issues hosted on GitHub (github.com/open-telemetry). These links are informative and point to trusted industry resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves scanning a user's codebase, which is a potential ingestion point for untrusted data. However, the skill mitigates this risk by defining a rigorous 'Migration Checklist' and a 'Required Completion Loop' that requires manual verification and evidence for every change, ensuring the agent remains focused on the technical migration task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:38 AM
Security Audit — agent-trust-hub — otel-span-events-to-logs-migration