zephyr-grafana-links
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from bake logs to identify event times and labels such as 'bake_done', 'fed', or 'mix'. This creates a surface for indirect prompt injection. * Ingestion points: Reads from the '## bake log' and '## Starter peak duration' sections of local bake log files. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified. * Capability inventory: Ability to write to local files and commit changes to the repository. * Sanitization: No sanitization or validation of the log content is performed before use.
- [COMMAND_EXECUTION]: The skill is instructed to commit bake logs after updating links, which involves version control command execution.
- [SAFE]: The skill references the official Grafana Cloud domain ('grafana.net') for dashboard links, which is a well-known service.
Audit Metadata