monitoring-expert

Fail

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation URL 'https://jeffallan.github.io/claude-skills/skills/devops/monitoring-expert/' is explicitly flagged by automated reputation scanners (URLite) as malicious.
  • [COMMAND_EXECUTION]: The skill provides instructions for activities that involve significant system impact and potential privilege requirements:
  • Recommends global installation of software packages via 'npm install -g clinic'.
  • Instructs the user to run process sampling and profiling tools like 'py-spy' and 'async-profiler', which inspect running processes and may require elevated privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, potentially untrusted sources such as application logs and distributed traces.
  • Ingestion points: Processes structured logs in 'references/structured-logging.md' and OpenTelemetry spans in 'references/opentelemetry.md'.
  • Boundary markers: The skill lacks explicit instructions or markers to distinguish untrusted data from system prompts, creating a surface for indirect injection.
  • Capability inventory: The skill environment has capabilities for process monitoring, file writing (heap snapshots/profiles), and network requests (load testing tools).
  • Sanitization: While the skill warns against logging PII, it does not include sanitization logic to prevent malicious instructions embedded in logs or traces from influencing the agent.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 7, 2026, 11:19 AM
Security Audit — agent-trust-hub — monitoring-expert