monitoring-expert

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate technical documentation and configuration examples for standard DevOps tools including Prometheus, Grafana, OpenTelemetry, and structured logging libraries like Pino and Structlog.
  • [SAFE]: Explicit security constraints are provided in the instructions, such as the mandatory redaction of sensitive data (passwords, tokens, PII) from logs and the use of correlation IDs for distributed tracing.
  • [EXTERNAL_DOWNLOADS]: Recommends installation of well-known performance and profiling tools such as clinic.js, py-spy, k6, and Artillery. These are reputable open-source tools within the technology community.
  • [COMMAND_EXECUTION]: Includes standard command-line examples for application profiling, load testing, and database query analysis (e.g., clinic doctor, py-spy top, EXPLAIN ANALYZE). These operations are consistent with the skill's stated purpose as a monitoring expert.
  • [SAFE]: All network-related examples (e.g., OpenTelemetry exporters, Prometheus scrapers) target internal or user-controlled endpoints like localhost or standard container service names (jaeger:4318), posing no exfiltration risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 10:32 AM
Security Audit — agent-trust-hub — monitoring-expert