otel-name-metric

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches metric naming specifications and semantic conventions from official OpenTelemetry (opentelemetry.io) documentation. These are well-known technology resources used correctly to provide the agent with up-to-date technical standards.
  • [COMMAND_EXECUTION]: The skill configuration allows for shell tool access, but the instructions are restricted to documentation review and naming validation without any suspicious command execution or shell scripting.
  • [SAFE]: Analysis of the skill instructions and reference documents revealed no evidence of prompt injection, obfuscation techniques, or attempts to harvest credentials or sensitive files.
  • [SAFE]: The skill has an indirect prompt injection surface as it processes external metric definitions provided by users.
  • Ingestion points: User-supplied metric names and definitions (SKILL.md).
  • Boundary markers: None implemented in the current instructions.
  • Capability inventory: The skill is configured with Shell, Write, Read, and AskUserQuestion tools.
  • Sanitization: There are no specific instructions for sanitizing or escaping the metric data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 06:54 PM
Security Audit — agent-trust-hub — otel-name-metric