otel-onboarding-style
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to inline the Superlog public ingest token directly into the bootstrap source code instead of using environment variables. While the vendor describes these tokens as public-scoped and safe for inlining (similar to a Sentry DSN), hardcoding any form of token is a deviation from standard secret management best practices that favor environment variables.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of several packages from public registries, including the vendor-owned package @superlog/otel-helpers, well-known industry-standard OpenTelemetry instrumentation libraries (such as @opentelemetry/instrumentation-http and various framework-specific Python packages), and the arizeai openinference instrumentation package for LLMs.
Audit Metadata