signoz-managing-views

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied intent to generate API payloads for creating, updating, and deleting views in SigNoz. This presents a potential surface for indirect injection if a user attempts to save malicious instructions.
  • Ingestion points: View names, display labels, and filter intent are accepted from the user as described in SKILL.md.
  • Boundary markers: The skill requires an explicit preview and user confirmation (for human-in-the-loop) or detailed logging (for autonomous agents) before performing any write operations. It explicitly warns against fabricating payloads.
  • Capability inventory: The skill uses signoz_create_view, signoz_update_view, and signoz_delete_view tools, which perform authenticated write actions on the SigNoz platform.
  • Sanitization: The skill effectively mitigates injection risks by delegating query construction to a specialized validation skill (signoz-generating-queries) and performing a mandatory 'sample fetch' to verify the exact filter against live data before persistence, ensuring the view matches expected data signal rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:12 AM
Security Audit — agent-trust-hub — signoz-managing-views