investigating-metric-anomalies
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of natural language instructions for troubleshooting infrastructure incidents. It does not include executable scripts, hardcoded credentials, or remote code downloads.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external data sources such as logs and metrics. Ingestion points:
query-logs,query-metrics,query-apm-spans. Boundary markers: absent. Capability inventory: read-only observability tools. Sanitization: absent. While this creates a potential surface for indirect injection, the risk is minimal as the tools are limited to data retrieval and the behavior is inherent to the skill's primary diagnostic purpose.
Audit Metadata