collecting-infrastructure-metrics

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for infrastructure monitoring and uses well-known, trusted services such as Prometheus, Datadog, and CloudWatch to collect system performance data.
  • [COMMAND_EXECUTION]: The skill utilizes scoped bash commands (e.g., Bash(metrics:*), Bash(monitoring:*)) to automate the installation and configuration of monitoring agents, which is consistent with its stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing user-driven monitoring requests which are used to generate configurations and execute commands.
  • Ingestion points: User-supplied phrases related to monitoring infrastructure performance (SKILL.md).
  • Boundary markers: Absent from the provided instructions.
  • Capability inventory: Includes file writing and scoped bash execution for system monitoring tasks (SKILL.md).
  • Sanitization: No explicit sanitization of user-provided monitoring targets is mentioned in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 10:18 PM
Security Audit — agent-trust-hub — collecting-infrastructure-metrics