observe-trace
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation contains a CLI alternative command using
npx @claude-flow/cli@latest. Running external packages using the@latestversion tag fetches code dynamically from the npm registry, introducing a potential supply chain risk if the package is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests and processes trace data from external tasks.
- Ingestion points: External trace spans are fetched from
mcp__plugin_ruflo-core_ruflo__memory_searchandmcp__plugin_ruflo-core_ruflo__memory_listinSKILL.md. - Boundary markers: There are no explicit delimiter or boundary controls defined to isolate the untrusted span content.
- Capability inventory: The execution environment includes access to the
Bashtool and metadata synthesis plugins. - Sanitization: No sanitization or escaping mechanisms are implemented for the fetched trace metrics and names before processing.
Audit Metadata