signoz-searching-docs
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves documentation files and sitemaps from the official signoz.io domain via HTTP GET requests and dedicated MCP tools. This is the primary function of the skill and uses the vendor's official infrastructure.
- [INDIRECT_PROMPT_INJECTION]: The skill processes content fetched from external documentation pages, which acts as a data ingestion point.
- Ingestion points: Documentation content is fetched from signoz.io as defined in the SKILL.md workflow and through the signoz_fetch_doc tool.
- Boundary markers: The instructions do not define specific delimiters to separate documentation content from the agent's internal reasoning or user instructions.
- Capability inventory: The skill is primarily focused on documentation lookup and response synthesis; more powerful actions are restricted to separate action-oriented skills.
- Sanitization: The retrieved markdown content is used directly for response generation without an intermediate filtering or validation step.
Audit Metadata