dashboard-builder
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill does not include any code, scripts, or automation logic. It is composed entirely of markdown instructions for the agent to follow when assisting a user with dashboard design.
- [SAFE]: The skill promotes operational best practices for monitoring systems like Grafana, Kafka, and Elasticsearch. It does not perform network operations, access sensitive files, or attempt to bypass security guardrails.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to inspect existing dashboards, creating a potential surface for indirect prompt injection if the target data is untrusted. Ingestion points: existing dashboard JSON files and platform schemas in SKILL.md. Boundary markers: absent. Capability inventory: limited to dashboard creation and JSON manipulation instructions. Sanitization: absent.
Audit Metadata