parallel-monitor
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content fetched from external websites through the
parallel-cli monitor eventsandevent-groupcommands, which introduces a surface for indirect prompt injection. - Ingestion points: Data retrieved from external web sources via
parallel-cli monitor eventsandparallel-cli monitor event-groupinSKILL.md. - Boundary markers: The instructions do not specify any boundary markers, delimiters, or system instructions to ignore potential commands embedded in the fetched web content.
- Capability inventory: The skill is scoped to
Bash(parallel-cli:*)which allows the agent to create, list, view, update, and delete server-side monitoring jobs. - Sanitization: No explicit sanitization, filtering, or validation of the retrieved web data is described before the agent summarizes the changes.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for maintaining its underlying CLI tool via official update paths.
- Evidence: Mentions the use of
parallel-cli updateandpipx upgrade parallel-web-toolsfor version management.
Audit Metadata