dashboards
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to process and author Grafana dashboard JSON models, which are externally provided data structures. While this represents a potential ingestion point for untrusted instructions, the skill includes explicit security warnings and best practices for the agent. For example, it warns that 'Actions' in Grafana trigger unauthenticated API calls and that tag-filtered annotation queries can leak data across an organization. It mandates auditing these features and treating API targets as user-visible, effectively mitigating the risk of accidental exploitation of these features through instructions found in dashboard data.
Audit Metadata