trace

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as an orchestration layer that ingests and analyzes untrusted data from multiple external sources.
  • Ingestion points: The skill accepts a user-provided observation via the <observation to trace> argument and directs agents to gather evidence from external sources including logs, source code, configurations, and tool outputs like trace_timeline and trace_summary (SKILL.md).
  • Boundary markers: The instructions lack explicit requirements for agents to use delimiters or 'ignore embedded instructions' markers when processing external data.
  • Capability inventory: The agent environment includes capabilities for reading files, accessing logs, and retrieving system trace information to validate hypotheses.
  • Sanitization: There are no defined protocols for sanitizing or filtering potentially malicious instructions that could be embedded within the logs or code artifacts being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — trace