observability-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a persona that analyzes untrusted external data such as logs, traces, and metrics, which provides a potential vector for indirect prompt injection. * Ingestion points: Processes application logs, distributed traces, and system metrics from enterprise environments (SKILL.md). * Boundary markers: The instructions do not define specific delimiters or guidelines to distinguish between instructions and data found within logs. * Capability inventory: While no code is provided, the skill describes capabilities for infrastructure automation (Terraform, Ansible) and interactions with monitoring platform APIs. * Sanitization: The skill includes general advice to avoid logging secrets but lacks specific data sanitization or validation logic for ingested telemetry.
  • [NO_CODE]: The skill consists entirely of markdown-based instructions and metadata; no scripts or executable code are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 03:55 PM
Security Audit — agent-trust-hub — observability-engineer