monitoring-stack
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The script
scripts/stack-health.shprogrammatically extracts a Telegram bot token from the local configuration file~/docker/stacks/monitoring/alertmanager/config.ymlfor use in API calls. - [REMOTE_CODE_EXECUTION]: Multiple commands in
SKILL.md,references/alert-rules-guide.md, andscripts/stack-health.shpipe output fromcurldirectly topython3 -cfor parsing. While the Python scripts are provided as static strings in the command line, this pattern involves executing code against data retrieved from network endpoints. - [COMMAND_EXECUTION]: The skill provides instructions and scripts that execute shell commands, manage Docker containers via
docker compose, and interact with service APIs usingcurl. - [INDIRECT_PROMPT_INJECTION]: The skill processes and displays data from Prometheus and Alertmanager APIs. If an attacker can control metric labels or alert names in the monitoring system, they could potentially inject malicious instructions into the agent's context.
- Ingestion points: Data is ingested from local Prometheus endpoints (
/api/v1/rules,/api/v1/alerts) and the Telegram bot API. - Boundary markers: None identified; output from these services is processed and printed directly.
- Capability inventory: The skill has the ability to execute shell commands, manage system services via Docker, read local configuration files, and perform network operations.
- Sanitization: None; the scripts parse raw JSON data and print specific fields to the terminal without escaping or validation.
Recommendations
- HIGH: Downloads and executes remote code from: http://localhost:9472/api/v1/alerts, http://localhost:9472/api/v1/rules, https://api.telegram.org/bot${BOT_TOKEN}/getMe - DO NOT USE without thorough review
Audit Metadata