superlog-onboard

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill inspects external repository files, workspace configuration manifests, and project source code across all discovered services. There are no explicit boundary markers or isolation strategies implemented to prevent the agent from processing malicious instructions that could be embedded inside these external project files. The agent maintains powerful capabilities including file modification, dependency installation, and local command execution during this workflow.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute system utilities to open web browsers (open, xdg-open, start), run the repository's native development or build commands to validate telemetry streams, and run configuration commands like claude mcp add to register a remote MCP server. The skill implements safety gates instructing the agent to obtain user confirmation before executing deployment or MCP setup steps.
  • [EXTERNAL_DOWNLOADS]: The skill manages the integration of native OpenTelemetry packages via the project's package managers and references a remote MCP server setup at https://api.superlog.sh/mcp. These external endpoints and packages correspond directly to the vendor's domain and operational infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:04 PM
Security Audit — agent-trust-hub — superlog-onboard