tracekit-ruby-sdk

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local script ./scripts/run-tracekit-auth.sh to manage authentication and registration. This operation is documented as part of the bootstrap process and is used to automate credential management for the user.
  • [DATA_EXFILTRATION]: Configures the application to transmit telemetry and traces to the vendor's official domain at app.tracekit.dev. This is the expected behavior for an Application Performance Monitoring (APM) tool and aligns with the stated service purpose.
  • [PROMPT_INJECTION]: The skill contains instructions specifying how to guide the user through the authentication flow, including a directive to prioritize automated checks over manual setup instructions. While these types of directives can be flagged as concealment, in this context they represent functional guidance for the agent's interaction style and do not constitute a bypass of safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 12:37 PM