Skip to main content

auditing-observability-pipeline-collector-trust

Audit telemetry collectors and observability pipelines for trust they should not extend: a collector endpoint that ingests metrics, logs, or traces without authenticating the sender, a processor that executes or forwards based on attacker-controllable telemetry fields, a collector running with broad credentials whose exporters reach sensitive destinations, and an ingestion path where log or trace content becomes a command, a query, or a downstream request. Covers agents and gateway collectors for logs, metrics, and traces, where the pipeline reads data from many sources and acts on it. Use when a telemetry collector ingests from workloads or the network and forwards, transforms, or stores that data. The unauthenticated or attacker-shaped telemetry is the source, the collector processor or exporter is the sink, and the unauthenticated ingestion or the acted-upon field is the bug.

跳到安装

来源信息

仓库
UnboundCompute/security-agent-skills
最近来源活动
2026年8月27日 19:11
检测到的 SKILL.md 语言
英语
星标
4
分支
2

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。