ln-627-observability-auditor
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to fetch markdown-based reference documents and reporting templates from the author's GitHub repository (github.com/levnikolaevich/claude-code-skills) using the WebFetch tool if the local shared directory is unavailable.- [COMMAND_EXECUTION]: Uses Bash, Grep, and specialized graph analysis tools to identify observability patterns within the codebase being audited. These operations are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted codebase data. Ingestion points: local codebase files read via Grep and Read tools; Boundary markers: none specified in instructions; Capability inventory: Bash, Read, Grep, Glob, and file writing for reports; Sanitization: no explicit filtering or sanitization of codebase content is mentioned.- [SAFE]: No evidence of malicious intent, unauthorized persistence, credential theft, or suspicious data exfiltration was found. The skill's behavior aligns with its documented role as an observability auditor.
Audit Metadata