parallel-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executeparallel-clicommands. These operations are restricted to theparallel-cli:*scope, which follows the principle of least privilege for the tool execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external websites during monitoring activities. This represents a potential attack surface if monitored content contains instructions designed to influence the agent's behavior during summarization or event reporting.
- Ingestion points: External web content is ingested through the
parallel-cli monitor eventscommand output (SKILL.md). - Boundary markers: None explicitly defined in the prompt instructions.
- Capability inventory: File system access and network operations are mediated through the
parallel-clitool. - Sanitization: The skill relies on the agent's default processing and the CLI's internal handling of web data.
- [DATA_EXFILTRATION]: The skill supports a
--webhookflag, which allows the agent to send monitoring event data to an external URL. While this is a documented feature for automated alerts, it creates a mechanism for sending web-derived data to third-party endpoints.
Audit Metadata