arize-annotation

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements robust security practices for handling sensitive credentials. It explicitly instructs users to manage the ARIZE_API_KEY via environment variables and CLI profiles, preventing the accidental exposure of secrets in chat logs or shell history.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official vendor-supported tools, including the arize-ax-cli and the arize Python SDK, through standard package managers like pip and uv. These are recognized as legitimate resources for interacting with the Arize platform.
  • [COMMAND_EXECUTION]: Shell commands involving the ax CLI are used for administrative tasks such as creating and managing annotation configurations. These operations are limited to the skill's functional scope and do not involve unauthorized privilege escalation or dangerous command patterns.
  • [DATA_EXFILTRATION]: Network activity and data operations are restricted to the official vendor domain (arize.com). There is no evidence of data being directed to unverified third-party endpoints or unknown external servers.
  • [PROMPT_INJECTION]: The instructions focus purely on operational tasks and troubleshooting. There are no attempts to override agent safety protocols, bypass constraints, or extract internal system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 08:19 PM