alert-investigator

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions explicitly direct the agent to use run_shell_command with kubectl to inspect the status of Kubernetes resources like Pods, Deployments, and Nodes. While these commands are intended for infrastructure troubleshooting, shell execution represents a significant capability within the environment.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external infrastructure sources.\n
  • Ingestion points: Data is retrieved via grafana__query_loki_logs, grafana__query_loki_patterns, and alert annotations (summary and description) from grafana__list_alert_rules.\n
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent regarding the potential for malicious content within logs or alert metadata.\n
  • Capability inventory: The agent utilizes various Grafana data source query tools and is instructed to execute shell commands (run_shell_command).\n
  • Sanitization: Absent. There are no instructions or tools provided to sanitize, filter, or validate the content retrieved from external logs before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:17 AM
Security Audit — agent-trust-hub — alert-investigator