otel-name-span
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill fetches naming guidance from official and trusted OpenTelemetry repositories and documentation sites. This behavior is consistent with the skill's primary purpose and targets well-known technology domains.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to prioritize and follow content retrieved from external URLs over its own internal rules.
- Ingestion points: Retrieval of external specifications from opentelemetry.io and processing of user-supplied span definitions (SKILL.md).
- Boundary markers: The instructions lack explicit delimiters or markers to isolate fetched content from the agent's control logic.
- Capability inventory: The skill is permitted to use Shell, Read, and Write tools (SKILL.md).
- Sanitization: There is no specified validation or sanitization process for content fetched from external documentation sources.
Audit Metadata