signoz-investigating-alerts
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including SigNoz alert history, trace status messages, and log bodies.
- Ingestion points: Data is ingested via
signoz_get_alert_history,signoz_search_traces, andsignoz_search_logsas described in the Workflow (SKILL.md). - Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded commands within the logs or trace data.
- Capability inventory: The skill uses SigNoz-specific tools (such as
signoz_execute_builder_queryandsignoz_search_traces) which are read-only operations for data retrieval and analysis. - Sanitization: No specific sanitization or filtering of log/trace content is mentioned before presenting findings to the user.
Audit Metadata