monitoring-observability

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard boilerplate code for application instrumentation and infrastructure monitoring. The implementation uses well-known, reputable libraries (express, prom-client, winston) and follows established patterns for metrics and logging collection.\n- [PROMPT_INJECTION]: The skill incorporates external inputs, such as HTTP request paths and headers, into monitoring metrics and log files. This represents an indirect prompt injection surface where malicious data could be processed by log analysis tools. However, the risk is low as the skill specifies structured JSON logging and includes a mandatory constraint to never log passwords or API keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 01:20 PM