signoz-explaining-alerts

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external alert data that may contain malicious instructions.\n
  • Ingestion points: The workflow in SKILL.md ingests alert configurations, history, and annotations through signoz_get_alert and signoz_get_alert_history.\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to isolate or ignore instructions that might be embedded within user-defined alert fields.\n
  • Capability inventory: The skill has the capability to read monitoring configurations and interact with the user. While instructed to be read-only, it operates in an environment where other tools in the same suite can modify alert states.\n
  • Sanitization: The instructions do not define any sanitization or validation processes for the ingested alert data before it is presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:35 AM
Security Audit — agent-trust-hub — signoz-explaining-alerts