zabbix-metrics-history

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill requires access to ZABBIX_URL and ZABBIX_TOKEN via environment variables. This is a standard and secure practice for managing sensitive credentials required for API authentication.
  • [EXTERNAL_DOWNLOADS]: The documentation references a third-party server component, zabbix-mcp, and identifies its source as a specific GitHub repository (mpeirone/zabbix-mcp-server) with a pinned commit. While the source is outside the common trusted vendor list, it is presented as a component source for a tool the skill describes as already vendored.
  • [PROMPT_INJECTION]: The skill includes instructions to the agent to follow a specific four-step procedure (e.g., calling item.get before history.get). These instructions are designed to prevent the AI from providing inaccurate information due to Zabbix API behavior and do not constitute an attempt to bypass safety filters.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external data from a Zabbix NMS.
  • Ingestion points: Data enters the context via the zabbix_api tool outputs.
  • Boundary markers: None explicitly defined in the provided instructions for the API responses.
  • Capability inventory: The skill uses tools to read data from an external API (zabbix_api) but contains no scripts or tools for file system modification or arbitrary command execution.
  • Sanitization: No specific sanitization or filtering logic is described for the incoming API data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:47 AM
Security Audit — agent-trust-hub — zabbix-metrics-history