monitoring-monte-carlo

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl, jq, and column to interact with the Monte Carlo GraphQL API and process the results into reports.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with https://api.getmontecarlo.com/graphql, which is the official endpoint for the Monte Carlo service.
  • [CREDENTIALS_UNSAFE]: The skill authenticates using MC_API_KEY_ID and MC_API_TOKEN environment variables. This is a standard and safe practice for secret management in AI agent skills.
  • [PROMPT_INJECTION]: The skill processes external data from API responses to generate reports, which constitutes a surface for indirect prompt injection. However, the use of GraphQL to request specific fields and structured processing with jq limits this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:28 AM
Security Audit — agent-trust-hub — monitoring-monte-carlo