investigating-with-observability

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Bash(curl:*), Bash(jq:*), and Bash(date:*) to perform its primary function: querying observability backends. All network operations are directed at endpoints defined by the user in environment variables (VM_METRICS_URL, VM_LOGS_URL, etc.). This is the intended behavior for an investigation skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as logs and traces.
  • Ingestion points: Data is fetched from VictoriaLogs, VictoriaMetrics, and VictoriaTraces backends via curl (defined in SKILL.md and all subagents).
  • Boundary markers: The skill emphasizes a structured "Investigation Protocol" and uses subagents to isolate data gathering from interpretation, which provides a natural boundary.
  • Capability inventory: The skill has access to shell tools (curl, jq, date), file reading, and agent dispatching.
  • Sanitization: Results are parsed using jq to extract specific fields, reducing the likelihood of raw malicious content influencing the agent's core logic.
  • [CREDENTIALS_UNSAFE]: The skill implements safe secret management. It uses the VM_CURL_CONFIG environment variable to point to a local file containing authentication headers, explicitly instructing the agent to never print the contents of this file. This avoids exposing credentials in process lists or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:49 PM
Security Audit — agent-trust-hub — investigating-with-observability