cx-olly
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the official
cxCLI tool to interact with Coralogix services. The commands documented, such ascx olly askandcx olly artifacts, are intended for observability analysis and artifact management. - [EXTERNAL_DOWNLOADS]: The skill involves downloading content from presigned URLs via the
cxCLI. These resources are part of the Coralogix infrastructure and are used to provide the user with requested charts and reports. - [PROMPT_INJECTION]: The skill facilitates the processing of observability data (logs, alerts, metrics) by an AI agent (Olly). While this establishes a surface for indirect prompt injection, no active exploitation or malicious redirection was found within the skill's instructions.
- Ingestion points: Response text from
cx olly askand downloaded content fromcx olly artifacts get. - Boundary markers: None specified in the skill configuration.
- Capability inventory: Execution of
cxCLI commands. - Sanitization: Not specified in the skill definition.
Audit Metadata