synthetic-monitoring-checks

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official Grafana domains (grafana.com, grafana.net) and library repositories (jslib.k6.io) for documentation and imports, which are trusted sources maintained by the vendor.
  • [SAFE]: Instructions for handling sensitive data strictly follow security best practices by utilizing the official k6/secrets module and providing placeholders for API tokens in examples, rather than hardcoding credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data such as OpenAPI/Swagger specifications, Postman collections, and GraphQL schemas to generate monitoring scripts, creating a potential attack surface.
  • Ingestion points: External API specifications and frontend XHR captures described in the 'Generating a check from an OpenAPI spec' section of SKILL.md.
  • Boundary markers: The instructions explicitly advise users to 'Filter for safety' and 'Verify the target URL' before deployment.
  • Capability inventory: The skill generates scripts capable of performing network operations (http.post, http.del) and browser interactions.
  • Sanitization: The documentation recommends validating response schemas and mapping credentials to managed secrets to prevent accidental exposure or injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:20 AM
Security Audit — agent-trust-hub — synthetic-monitoring-checks