signoz-creating-dashboards
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes natural language intents and incorporates data discovered from the SigNoz environment into executable queries and dashboard configurations.
- Ingestion points: User-provided intent and metadata fetched via tools like signoz_list_metrics and signoz_get_field_keys as described in SKILL.md.
- Boundary markers: Instructions mandate using representative literals for validation and explicitly warn against guessing resource scopes or metrics.
- Capability inventory: The agent uses signoz_create_dashboard for persistence and signoz_execute_builder_query for query validation.
- Sanitization: All custom configurations require a mandatory dry-run and a plain-language preview for user confirmation before execution to prevent unintended dashboard creation.\n- [COMMAND_EXECUTION]: The documentation references a vendor-specific setup utility for environment initialization.
- Evidence: SKILL.md mentions running signoz-mcp-setup to initialize or repair the MCP connection if SigNoz tools are unavailable. This is presented as a prerequisite setup step for the vendor infrastructure.
Audit Metadata