alert-investigator
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions explicitly direct the agent to use
run_shell_commandwithkubectlto inspect the status of Kubernetes resources like Pods, Deployments, and Nodes. While these commands are intended for infrastructure troubleshooting, shell execution represents a significant capability within the environment.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external infrastructure sources.\n - Ingestion points: Data is retrieved via
grafana__query_loki_logs,grafana__query_loki_patterns, and alert annotations (summaryanddescription) fromgrafana__list_alert_rules.\n - Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent regarding the potential for malicious content within logs or alert metadata.\n
- Capability inventory: The agent utilizes various Grafana data source query tools and is instructed to execute shell commands (
run_shell_command).\n - Sanitization: Absent. There are no instructions or tools provided to sanitize, filter, or validate the content retrieved from external logs before processing it.
Audit Metadata