alert-investigation

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external, untrusted telemetry data from observability sources.\n
  • Ingestion points: Data is ingested through tools described in logs.md (query-logs), errors.md (query-error-groups), sessions.md (query-sessions, query-timeline-events), and traces.md (query-traces).\n
  • Boundary markers: Absent. The instructions do not define clear delimiters or instruct the agent to ignore potential instructions embedded within the retrieved telemetry data.\n
  • Capability inventory: The skill is limited to querying telemetry data and producing structured text diagnoses; it does not contain capabilities for arbitrary shell command execution, file system modification, or non-whitelisted network communication.\n
  • Sanitization: Absent. There are no mechanisms described to sanitize or validate the content of log lines, error messages, or session attributes before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 10:26 PM
Security Audit — agent-trust-hub — alert-investigation