monitoring-monte-carlo
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curl,jq, andcolumnto interact with the Monte Carlo GraphQL API and process the results into reports. - [EXTERNAL_DOWNLOADS]: The skill communicates with
https://api.getmontecarlo.com/graphql, which is the official endpoint for the Monte Carlo service. - [CREDENTIALS_UNSAFE]: The skill authenticates using
MC_API_KEY_IDandMC_API_TOKENenvironment variables. This is a standard and safe practice for secret management in AI agent skills. - [PROMPT_INJECTION]: The skill processes external data from API responses to generate reports, which constitutes a surface for indirect prompt injection. However, the use of GraphQL to request specific fields and structured processing with
jqlimits this risk.
Audit Metadata