alert-investigation
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external, untrusted telemetry data from observability sources.\n
- Ingestion points: Data is ingested through tools described in
logs.md(query-logs),errors.md(query-error-groups),sessions.md(query-sessions,query-timeline-events), andtraces.md(query-traces).\n - Boundary markers: Absent. The instructions do not define clear delimiters or instruct the agent to ignore potential instructions embedded within the retrieved telemetry data.\n
- Capability inventory: The skill is limited to querying telemetry data and producing structured text diagnoses; it does not contain capabilities for arbitrary shell command execution, file system modification, or non-whitelisted network communication.\n
- Sanitization: Absent. There are no mechanisms described to sanitize or validate the content of log lines, error messages, or session attributes before they are processed by the agent.
Audit Metadata