grafana-prometheus
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The monitoring content is largely coherent, but the MCP integration is inconsistent with Grafana’s official distribution path: it uses an unverified `npx` package name and forwards a Grafana API token into it. That creates a disproportionate supply-chain and credential-forwarding risk relative to an otherwise benign observability skill.
Confidence: 88%Severity: 86%
Audit Metadata