agent-performance-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation includes operational commands that utilize
npxto execute theclaude-flowCLI tool for health checks, bottleneck analysis, and metrics collection. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external data without explicit sanitization.
- Ingestion points: Data is ingested via
mcp.agent_list,mcp.agent_metrics, andmcp.health_checkcalls (found inSKILL.md). - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the provided metrics processing logic.
- Capability inventory: The skill includes the capability to execute shell commands via the
claude-flowCLI and performs system-level resource tracking (found inSKILL.md). - Sanitization: No escaping, validation, or filtering logic is provided for the data retrieved from external agents or system metrics before it is processed or used in analysis.
Audit Metadata