trace-triage

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official MCP endpoint at https://mcp.observability.progress.com/mcp to retrieve trace metadata and content. This communication is restricted to the skill's primary purpose and uses the vendor's own infrastructure.
  • [DATA_EXFILTRATION]: To prevent unintended data exposure, the skill includes explicit instructions to scrub PII (such as emails, phone numbers, and SSNs) from any trace content before it is reported to the user.
  • [COMMAND_EXECUTION]: The documentation provides a curl command for manual connectivity verification. This is intended for developer troubleshooting and is not an automated execution pattern.
  • [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection by instructing the agent to treat ingested trace content exclusively as data for analysis, never as instructions. It further mandates the defanging of control tokens (e.g., ChatML or HTML tags) within quoted content to prevent context escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 03:57 PM
Security Audit — agent-trust-hub — trace-triage