signoz-setting-up-observability
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured workflow for managing SigNoz observability artifacts using native MCP tools. No malicious command execution or unauthorized data access patterns were detected.
- [DATA_EXPOSURE]: The instructions include defensive filtering patterns to exclude sensitive file paths (such as .env, .git, .aws, and .ssh) from being processed as valid telemetry events, which prevents accidental exposure of scanning attempts in monitoring dashboards.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies the potential for ingesting untrusted telemetry data and mitigates risks by requiring field verification via discovery tools and instructing the agent to avoid high-cardinality labels that could lead to data leakage or performance degradation.
Audit Metadata