k6-cloud-investigate-test

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the gcx command-line interface to perform authenticated operations against Grafana Cloud stacks, such as connectivity checks, API resource retrieval, and test script management. \n- [DATA_EXFILTRATION]: The skill retrieves performance metrics, execution logs via Loki, and test scripts from Grafana Cloud for the purpose of diagnosis. It also uses the /tmp directory for temporary storage of this information. \n- [PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources, specifically execution logs and test scripts, creating a surface for indirect prompt injection. \n
  • Ingestion points: Test scripts (Step 2) and execution logs (Step 7) in SKILL.md. \n
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the processed log and script data. \n
  • Capability inventory: The agent can execute shell commands via gcx and update cloud-hosted scripts. \n
  • Sanitization: No sanitization of external log or script content is performed prior to inclusion in the diagnostic report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 04:46 PM
Security Audit — agent-trust-hub — k6-cloud-investigate-test