signoz-investigating-alerts

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including SigNoz alert history, trace status messages, and log bodies.
  • Ingestion points: Data is ingested via signoz_get_alert_history, signoz_search_traces, and signoz_search_logs as described in the Workflow (SKILL.md).
  • Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded commands within the logs or trace data.
  • Capability inventory: The skill uses SigNoz-specific tools (such as signoz_execute_builder_query and signoz_search_traces) which are read-only operations for data retrieval and analysis.
  • Sanitization: No specific sanitization or filtering of log/trace content is mentioned before presenting findings to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:35 AM
Security Audit — agent-trust-hub — signoz-investigating-alerts