kuma-operations

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the kuma-pp-cli binary. It uses npx to install the @mvanhorn/printing-press-library package and go install for the github.com/mvanhorn/printing-press-library repository. Both sources are associated with the author.\n- [COMMAND_EXECUTION]: The skill is designed to drive shell commands via the kuma-pp-cli and kumactl-mcp binaries for health checks, monitor inspection, and configuration updates.\n- [INDIRECT_PROMPT_INJECTION]:\n
  • Ingestion points: Data is ingested from an external Uptime Kuma instance through commands like kuma-pp-cli monitors --json and kuma-pp-cli incident-context in SKILL.md.\n
  • Boundary markers: None explicitly defined in the provided instructions.\n
  • Capability inventory: The skill can execute various CLI commands in SKILL.md to read and modify monitor configurations.\n
  • Sanitization: None specified for the data retrieved from the monitoring service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:59 PM
Security Audit — agent-trust-hub — kuma-operations