apitally-cli
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
npxto execute the@apitally/clipackage, which involves fetching and running the official package from the npm registry. - [COMMAND_EXECUTION]: The skill runs shell commands and SQL queries via the Apitally CLI to retrieve metrics and investigate logs.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API logs, which represents a surface for indirect prompt injection if those logs contain malicious instructions.
- Ingestion points: API request logs and metrics retrieved via the CLI (SKILL.md, references/commands.md).
- Boundary markers: Instructions emphasize using SQL filters for
app_idandtimestampto limit the scope of investigations. - Capability inventory: Shell command execution (
npx) and SQL query execution against a local DuckDB instance. - Sanitization: The skill processes data in structured NDJSON and JSON formats and queries it via SQL.
Audit Metadata