monitoring-observability

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing various open-source packages and Docker images from well-known services and trusted organizations, including Langfuse, Arize Phoenix, LiteLLM, and OpenTelemetry.
  • [CREDENTIALS_UNSAFE]: Documentation and configuration templates (such as Docker Compose files and environment variable checklists) include example placeholder keys and passwords intended for local development and setup guidance. These are clearly marked as placeholders (e.g., 'CHANGE_ME_strong_password', 'pk-lf-dev').
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands for installing dependencies, running Docker containers, and using CLI tools for monitoring. These are educational patterns and do not involve the execution of arbitrary or malicious scripts.
  • [DATA_EXPOSURE]: The skill outlines patterns for collecting application metrics and traces. It includes best practices for cardinality management and data truncation to prevent sensitive information from being inadvertently stored in observability backends.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes methods for processing and evaluating LLM outputs and traces. While this creates a surface area for processing untrusted data, the skill includes patterns for sanitization and uses semantic classification to isolate different stages of agent execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 12:56 PM