kubespray-monitoring

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). This SKILL.md explicitly instructs downloading community dashboards from grafana.com (see "Download Community Dashboards" curl commands) which fetches public, user-contributed JSON dashboards that are ingested and loaded into Grafana as part of the workflow, so untrusted third-party content could influence monitoring/alerting behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill instructs editing system-level configuration (etcd, /etc/exports), running an Ansible playbook with privilege escalation (-b), and uses sudo-level troubleshooting commands — all of which modify system files/services and require root access.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 04:44 AM