signoz-investigating-alerts

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted telemetry data from external sources. While this content is untrusted, the skill's structured analysis workflow and focus on statistical correlation minimize the risk of the agent following embedded instructions. Ingestion points: Data is ingested via signoz:signoz_search_traces and signoz:signoz_search_logs as described in SKILL.md. Boundary markers: None explicitly defined. Capability inventory: Includes tool calls for querying metrics and retrieving alert details. Sanitization: Content is grouped and summarized, but no specific escaping or filtering of log/trace bodies is mentioned.
  • [DATA_EXPOSURE]: The skill accesses service metrics and logs via official SigNoz tools. This behavior is consistent with the skill's stated purpose and uses established vendor interfaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 08:01 PM