investigating-with-observability
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
Bash(curl:*),Bash(jq:*), andBash(date:*)to perform its primary function: querying observability backends. All network operations are directed at endpoints defined by the user in environment variables (VM_METRICS_URL,VM_LOGS_URL, etc.). This is the intended behavior for an investigation skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as logs and traces.
- Ingestion points: Data is fetched from VictoriaLogs, VictoriaMetrics, and VictoriaTraces backends via
curl(defined inSKILL.mdand all subagents). - Boundary markers: The skill emphasizes a structured "Investigation Protocol" and uses subagents to isolate data gathering from interpretation, which provides a natural boundary.
- Capability inventory: The skill has access to shell tools (
curl,jq,date), file reading, and agent dispatching. - Sanitization: Results are parsed using
jqto extract specific fields, reducing the likelihood of raw malicious content influencing the agent's core logic. - [CREDENTIALS_UNSAFE]: The skill implements safe secret management. It uses the
VM_CURL_CONFIGenvironment variable to point to a local file containing authentication headers, explicitly instructing the agent to never print the contents of this file. This avoids exposing credentials in process lists or logs.
Audit Metadata