signoz-creating-alerts

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied natural language intent to generate and execute monitoring queries and alert configurations.
  • Ingestion points: The skill takes alert intents from user input or $ARGUMENTS in SKILL.md (Step 1).
  • Boundary markers: Includes a mandatory human-readable summary (Step 8) and a dry-run validation step (Step 6) that computes fire counts before any alert is persisted.
  • Capability inventory: Uses signoz_execute_builder_query for dry-runs and signoz_create_alert for persistence.
  • Sanitization: Employs discovery tools (signoz_get_field_keys, signoz_list_metrics) to verify attribute and metric names against the system schema rather than relying on user input alone.
  • [CREDENTIALS_UNSAFE]: While the skill handles secrets (e.g., Slack webhooks, PagerDuty keys), it implements exemplary defense-in-depth measures to prevent exposure.
  • Evidence: SKILL.md (Step 7) explicitly forbids the agent from echoing secrets back to the user, storing them in clarification contexts, or retaining them beyond a single tool call to signoz_create_notification_channel.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:11 AM
Security Audit — agent-trust-hub — signoz-creating-alerts