signoz-generating-queries

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to the official SigNoz documentation for setup and configuration, which is a trusted source.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it processes observability data (logs and traces) which could be controlled by an external actor. This is documented as an inherent risk of processing such data.
  • Ingestion points: Logs and traces retrieved via 'signoz:signoz_search_logs' and 'signoz:signoz_search_traces' in 'SKILL.md'.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands in the data results are present.
  • Capability inventory: The skill uses a set of 'signoz:*' tools for data retrieval and can trigger an 'apply_filter' action in the UI.
  • Sanitization: No explicit sanitization of the retrieved observability data is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 02:06 AM
Security Audit — agent-trust-hub — signoz-generating-queries