monitoring-expert

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes clear security guidelines in its constraints, such as the requirement to redact sensitive data (PII, tokens, passwords) from logs.
  • [CREDENTIALS_UNSAFE]: The configuration examples for Alertmanager and other services use secure placeholders like 'your-key' and 'https://hooks.slack.com/...', preventing accidental exposure of real credentials.
  • [COMMAND_EXECUTION]: The application profiling documentation mentions common performance tools such as clinic.js, py-spy, and pprof. These commands are standard for debugging and optimizing applications and do not involve suspicious remote execution patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known libraries and tools from official package registries (NPM, PyPI) and established open-source projects (k6, Prometheus, OpenTelemetry). These are legitimate dependencies for an observability professional.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 07:57 AM
Security Audit — agent-trust-hub — monitoring-expert