holmesgpt-skill
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as documentation and configuration guidance for HolmesGPT. It contains no executable code or malicious logic.
- [EXTERNAL_DOWNLOADS]: The skill provides installation instructions that reference trusted and well-known sources, including the official 'robusta-dev' GitHub repository, the 'robusta-charts' Helm repository on Google Cloud Storage, and legitimate Homebrew taps. The Docker image resides on a known project-specific Google Artifact Registry path.
- [PROMPT_INJECTION]: The skill describes a tool that processes external observability data (logs, alerts). It proactively addresses injection risks by specifying that the tool operates with read-only RBAC permissions and focuses on analysis rather than resource modification.
- [SAFE]: Instructions for handling sensitive credentials (API keys for OpenAI, Anthropic, PagerDuty, etc.) follow industry best practices, advising the use of environment variables and Kubernetes Secrets while utilizing safe placeholders in examples.
Audit Metadata