signoz-creating-alerts
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied natural language intent to generate and execute monitoring queries and alert configurations.
- Ingestion points: The skill takes alert intents from user input or
$ARGUMENTSinSKILL.md(Step 1). - Boundary markers: Includes a mandatory human-readable summary (Step 8) and a dry-run validation step (Step 6) that computes fire counts before any alert is persisted.
- Capability inventory: Uses
signoz_execute_builder_queryfor dry-runs andsignoz_create_alertfor persistence. - Sanitization: Employs discovery tools (
signoz_get_field_keys,signoz_list_metrics) to verify attribute and metric names against the system schema rather than relying on user input alone. - [CREDENTIALS_UNSAFE]: While the skill handles secrets (e.g., Slack webhooks, PagerDuty keys), it implements exemplary defense-in-depth measures to prevent exposure.
- Evidence:
SKILL.md(Step 7) explicitly forbids the agent from echoing secrets back to the user, storing them in clarification contexts, or retaining them beyond a single tool call tosignoz_create_notification_channel.
Audit Metadata