otel-name-span

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill fetches naming guidance from official and trusted OpenTelemetry repositories and documentation sites. This behavior is consistent with the skill's primary purpose and targets well-known technology domains.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to prioritize and follow content retrieved from external URLs over its own internal rules.
  • Ingestion points: Retrieval of external specifications from opentelemetry.io and processing of user-supplied span definitions (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or markers to isolate fetched content from the agent's control logic.
  • Capability inventory: The skill is permitted to use Shell, Read, and Write tools (SKILL.md).
  • Sanitization: There is no specified validation or sanitization process for content fetched from external documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 06:54 PM