signoz-explaining-dashboards
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external dashboard configuration data (JSON) which represents a potential injection surface if the dashboard content (titles, descriptions) contains malicious instructions.
- Ingestion points: Data is ingested through the
signoz_get_dashboardtool response as described inSKILL.md. - Boundary markers: No specific delimiters are used for the interpolated dashboard content.
- Capability inventory: The skill's instructions are limited to generating natural language explanations; it does not include commands for file writing, network operations, or code execution.
- Sanitization: The instruction to "translate query intent into plain English" and "interpret" content serves as a semantic filter, treating the ingested data as information to be described rather than instructions to be followed.
- [COMMAND_EXECUTION]: The skill references a CLI command
signoz-mcp-setup. This is provided as troubleshooting advice for the user to initialize the required MCP server tools, rather than an instruction for the agent to execute commands autonomously or silently.
Audit Metadata