symfony-yoandev-observability
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes processing application logs and request headers (e.g., X-Request-Id) which can contain untrusted data.
- Ingestion points: CorrelationId class (SKILL.md), LogRecord processing (references/sensitive-data.md).
- Boundary markers: Instructions mandate using PSR-3 placeholders instead of string concatenation to maintain separation between instructions and data.
- Capability inventory: Monolog handlers are configured for network transmission (Slack/Sentry) and file writes (references/alerting.md).
- Sanitization: The RedactingProcessor implements key-based filtering for passwords, tokens, and PII; the correlation ID is validated against a strict alphanumeric regex.
- [DATA_EXPOSURE]: The skill includes extensive documentation and implementation patterns for preventing sensitive data exposure in production logs. It specifically highlights risks such as Doctrine's SQL parameter logging and the handling of authentication tokens in URLs.
- [EXTERNAL_DOWNLOADS]: Recommends standard observability tools like Sentry and Slack webhooks. These resources are from well-known services and are used according to best practices for production monitoring.
Audit Metadata