prd-v08-monitoring-setup
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a comprehensive documentation and template system for monitoring setup. The instructions and reference files are professional and do not contain obfuscation or direct malicious patterns.
- [EXTERNAL_DOWNLOADS]: The documentation contains informational references to official resources and established technology providers, such as Google SRE guides and monitoring platforms like Datadog and New Relic. These are recognized as well-known and trusted sources.
- [PROMPT_INJECTION]: The skill processes project-specific data to generate monitoring rules, which presents an indirect prompt injection surface.
- Ingestion points: The skill instructions direct the agent to read various project files, including RUN-, DEP-, API-, KPI-, ARC-, and TECH- entries.
- Boundary markers: There are no instructions for using delimiters or boundary markers to differentiate between the skill's instructions and the content of the processed files, nor are there warnings to ignore instructions embedded in those files.
- Capability inventory: The skill configuration includes access to the Bash, Write, Edit, and Read tools.
- Sanitization: The skill does not specify any validation or sanitization procedures for the data ingested from the project documentation.
Audit Metadata