exploring-apm-traces
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard instructional guide for using vendor-specific MCP tools (
posthog:*) to query and analyze application performance monitoring data. All resources and tools referenced align with the author's identity (PostHog). - [INDIRECT_PROMPT_INJECTION]: The skill processes external data (OpenTelemetry spans) retrieved from PostHog.
- Ingestion points: External span data enters the agent context via
posthog:query-apm-spansandposthog:apm-trace-getas described inSKILL.md. - Boundary markers: None identified in the skill instructions.
- Capability inventory: No file system writes, subprocess executions, or arbitrary network operations are defined within the skill content.
- Sanitization: No explicit sanitization or validation of the ingested span attributes is described.
Audit Metadata