Back to skill

Security audit

Agent Observability Stack: Distributed Tracing, Metrics, and Alerting for Multi-Agent Systems

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable observability guide with expected telemetry and alerting examples, but copied code should be configured to avoid sending sensitive business data to third parties.

Before copying the examples into production, decide what telemetry may leave your environment. Redact or hash customer, transaction, escrow, credential, and internal topology identifiers; use allowlisted HTTPS webhook destinations; and document retention and access controls for GreenHelix, Slack, and any observability backend.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:1698
Finding

Unrestricted Webhook Destination Enables SSRF and Alert Metadata Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:944
Finding

Unrestricted Metric Dimensions May Export Sensitive Data to an External Telemetry Service

Content
View full analysis
self._buffer_size * 2: self._buffer = self._buffer[-self._buffer_size:] for callback in self._flush_callbacks: try: callback(batch) except Exception: pass ``` ### Technical Analysis The collector copies every caller-provided dimension into `metrics_payload` and submits the resulting payload to GreenHelix. There is no allowlist, sensitivity classification, key-name validation, value redaction, size restriction, or cardinality control. Telemetry export is intrinsic to the declared observability functionality, and the client must receive some operational metrics. The excessive behavior is forwarding arbitrary dimensions rather than restricting export to the minimum fields required for each defined metri ...[truncated 2160 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide encourages sending traces, metrics, billing amounts, escrow identifiers, transaction IDs, and other operational/business metadata to GreenHelix and external observability backends without clearly warning that this telemetry may contain sensitive information. In practice, users often copy production examples verbatim, which can result in unintentional exposure of internal topology, financial data, and customer-linked identifiers to third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The webhook and Slack alerting examples transmit alert contents, metric values, agent IDs, and dimensions to third-party endpoints without a prominent warning about data disclosure risks. Because alert payloads often include operational state and can be expanded by users to include trace or transaction context, this pattern can leak sensitive fleet and business information outside the primary environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L1928 the inline comment says the code will "register webhook with GreenHelix for event-driven alerts," which implies creation of a webhook subscription. The actual implementation at L1931-L1942 only calls submit_metrics to emit an alerts.fired metric and never invokes register_webhook or any equivalent registration behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.