ln-627-observability-auditor

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is configured to fetch markdown-based reference documents and reporting templates from the author's GitHub repository (github.com/levnikolaevich/claude-code-skills) using the WebFetch tool if the local shared directory is unavailable.- [COMMAND_EXECUTION]: Uses Bash, Grep, and specialized graph analysis tools to identify observability patterns within the codebase being audited. These operations are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted codebase data. Ingestion points: local codebase files read via Grep and Read tools; Boundary markers: none specified in instructions; Capability inventory: Bash, Read, Grep, Glob, and file writing for reports; Sanitization: no explicit filtering or sanitization of codebase content is mentioned.- [SAFE]: No evidence of malicious intent, unauthorized persistence, credential theft, or suspicious data exfiltration was found. The skill's behavior aligns with its documented role as an observability auditor.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 07:48 AM