using-grafana-mcp

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill interacts with external monitoring data which presents an indirect prompt injection surface.\n
  • Ingestion points: query_loki_logs, query_prometheus, and get_incident (SKILL.md, references/TOOL-REFERENCE.md).\n
  • Boundary markers: Not specified.\n
  • Capability inventory: patch_dashboard, update_dashboard, and alerting_manage_rules (SKILL.md, references/DASHBOARDS-AND-EDIT.md).\n
  • Sanitization: The skill mandates user confirmation for mutation tools via the 'Write paths
  • pause and confirm' instruction (SKILL.md).\n- [COMMAND_EXECUTION]: The skill facilitates the execution of domain-specific query and modification logic.\n
  • Evidence: Tools like query_prometheus and patch_dashboard enable the agent to execute PromQL and JSON Patch operations.\n- [DATA_EXFILTRATION]: The skill provides access to potentially sensitive logs and administrative data.\n
  • Evidence: Tools retrieve application logs and user metadata, though these are within the intended scope of a monitoring integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 04:50 PM
Security Audit — agent-trust-hub — using-grafana-mcp