synthetic-monitoring-checks
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses official Grafana domains (grafana.com, grafana.net) and library repositories (jslib.k6.io) for documentation and imports, which are trusted sources maintained by the vendor.
- [SAFE]: Instructions for handling sensitive data strictly follow security best practices by utilizing the official
k6/secretsmodule and providing placeholders for API tokens in examples, rather than hardcoding credentials. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data such as OpenAPI/Swagger specifications, Postman collections, and GraphQL schemas to generate monitoring scripts, creating a potential attack surface.
- Ingestion points: External API specifications and frontend XHR captures described in the 'Generating a check from an OpenAPI spec' section of SKILL.md.
- Boundary markers: The instructions explicitly advise users to 'Filter for safety' and 'Verify the target URL' before deployment.
- Capability inventory: The skill generates scripts capable of performing network operations (
http.post,http.del) and browser interactions. - Sanitization: The documentation recommends validating response schemas and mapping credentials to managed secrets to prevent accidental exposure or injection.
Audit Metadata