vigil-instrument

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements standard observability instrumentation using OpenTelemetry. It provides guidance for Node.js, Python, and Go, focusing on RED metrics and distributed tracing correlation.\n- [SAFE]: Instructions include clear security warnings to avoid logging PII, passwords, tokens, API keys, and full request/response bodies, which mitigates data exposure risks during logging operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration files and source code to determine instrumentation needs, creating a potential surface for indirect prompt injection from untrusted repositories. However, the instructions focus on generating standard boilerplate and health checks with manual oversight.\n
  • Ingestion points: Reads repository metadata and source code (e.g., package.json, main files).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Accesses Write, Edit, and Bash tools to implement instrumentation code.\n
  • Sanitization: Not explicitly implemented in the prompt logic, but the output guidance emphasizes safe logging practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — vigil-instrument