monte-carlo-storage-cost-analysis
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill integrates with an official Monte Carlo MCP server (mcp.getmontecarlo.com) to perform its primary function. All network operations and tool interactions are consistent with the stated purpose of analyzing storage costs in Snowflake, BigQuery, Redshift, and Databricks. External references point to the vendor's own infrastructure.
- [SAFE]: No evidence of prompt injection or malicious role-play instructions was found. The skill includes instructions for the agent to preserve tool output formatting and MCON links, which are standard for maintaining user interface integrity and correct tool integration.
- [SAFE]: The skill does not access sensitive local files (like SSH keys or cloud provider credentials) or environment variables. It works exclusively with warehouse-specific identifiers and metadata provided by the user or the MCP tool.
- [SAFE]: Indirect prompt injection surfaces are managed via structured output regions. The skill ingests metadata from the warehouse tool and uses specific HTML comment markers (e.g., ) to identify sections for presentation, providing a structural boundary for external data. Capabilities are limited to metadata lookups and lineage analysis.
- [SAFE]: There are no signs of obfuscation, dynamic code execution, or persistence mechanisms. The skill's workflow is transparent and its functions are limited to retrieving and presenting storage waste data.
Audit Metadata