clay-observability

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains legitimate instructions and code samples for observability and monitoring. No malicious patterns or bypass attempts were detected.
  • [EXTERNAL_DOWNLOADS]: The skill references the well-known prom-client Node.js library for Prometheus instrumentation, which is standard for this use case.
  • [DATA_EXFILTRATION]: Provides a script to send reports to a Slack webhook. This uses the SLACK_WEBHOOK_URL environment variable, following best practices for secret management, and is intended for operational reporting rather than exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data (lead information from Clay webhooks). While these fields (email, company name, ICP score) are interpolated into reports and logs, the context is limited to data processing and doesn't present a high risk for agent manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 04:40 PM