cx-query-logs
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
cxCLI tool to execute log queries and metadata searches. This is the intended delivery mechanism for the vendor's log analysis functionality. - [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it ingests and processes application logs, which are untrusted external data sources.
- Ingestion points: Application log content retrieved via
cx logsinSKILL.md. - Boundary markers: None identified in the instructions to separate log data from agent instructions.
- Capability inventory: The agent has the ability to execute CLI commands (
cx logs,cx search-fields). - Sanitization: No specific sanitization or filtering of log data is required by the instructions.
- [SAFE]: No evidence of hardcoded credentials, malicious remote code downloads, or persistence mechanisms was found. The skill is authored by the service vendor and uses expected infrastructure and tools.
Audit Metadata