monte-carlo-monitoring-advisor
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access techniques were found in the skill. All operations are aligned with the stated purpose of assisting with data observability on the Monte Carlo platform.
- [NO_CODE]: The skill is composed entirely of instructional Markdown files and does not include any executable scripts, reducing the direct execution risk to the user's environment.
- [EXTERNAL_DOWNLOADS]: The skill's documentation directs users to install official vendor tools, specifically the
montecarlodataPython package and themc-agent-toolkitvia npx. These resources are from the verified vendor 'monte-carlo-data' and are required for the intended functionality. - [PROMPT_INJECTION]: The skill processes external data (such as table schemas and agent conversation logs) to generate monitoring recommendations. This represents an indirect prompt injection surface. However, the risk is mitigated as the skill only generates advisory text and configuration YAML intended for human review and manual deployment via a CLI, rather than taking autonomous actions on the user's behalf.
Audit Metadata