signoz-explaining-alerts
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external alert data that may contain malicious instructions.\n
- Ingestion points: The workflow in
SKILL.mdingests alert configurations, history, and annotations throughsignoz_get_alertandsignoz_get_alert_history.\n - Boundary markers: No explicit delimiters or instructions are provided to the agent to isolate or ignore instructions that might be embedded within user-defined alert fields.\n
- Capability inventory: The skill has the capability to read monitoring configurations and interact with the user. While instructed to be read-only, it operates in an environment where other tools in the same suite can modify alert states.\n
- Sanitization: The instructions do not define any sanitization or validation processes for the ingested alert data before it is presented to the user.
Audit Metadata