loki-label-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided log label strategies and metadata schemas to generate diagnostic reports. This creates an indirect prompt injection surface where instructions embedded in the analyzed data could theoretically attempt to influence the agent's report generation.
  • Ingestion points: The agent ingests user-provided label sets, log samples, and strategy descriptions as specified in SKILL.md.
  • Boundary markers: The skill employs strict output formatting requirements, mandatory verbatim disclaimers, and specific section headers which provide structural boundaries for the generated content.
  • Capability inventory: The skill's capabilities are limited to generating structured text reports and Grafana Alloy configuration templates. It does not perform unauthorized file writes, subprocess execution, or direct network operations.
  • Sanitization: The instructions focus on expert evaluation logic and do not explicitly define sanitization or escaping for user-provided identifiers included in the audit output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:02 AM
Security Audit — agent-trust-hub — loki-label-analyzer