prometheus-cardinality-troubleshooter

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to local Prometheus endpoints and official Grafana Cloud domains (grafana.net) using standard diagnostic APIs. These are expected for a troubleshooting tool from this vendor.
  • [CREDENTIALS_UNSAFE]: Access to Grafana Cloud APIs uses placeholders for credentials (":"), which is a secure documentation practice and does not involve hardcoded secrets.
  • [COMMAND_EXECUTION]: The skill provides bash and PromQL snippets for diagnostic purposes. Commands involve standard tools like curl, jq, and sort to process local or vendor-specific API responses.
  • [DATA_EXFILTRATION]: While the skill reads metrics data from Prometheus, it does not attempt to exfiltrate sensitive files (like SSH keys or AWS credentials) or send data to unauthorized third-party domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — prometheus-cardinality-troubleshooter