rpe-grafana

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed read-only Grafana integration, but users should treat returned dashboard metrics as potentially sensitive.

Install only with a trusted Grafana URL and a least-privileged Viewer or read-only service account. Do not provide admin credentials or access to dashboards the agent should not be allowed to read, because this skill can retrieve values from any visible dashboard and panel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The documentation explains that the skill executes existing panel queries through Grafana's datasource API using supplied credentials, but it does not clearly warn that dashboard requests, query definitions, and returned metric values may contain sensitive operational or business data. Users may invoke the skill without understanding that it transmits and retrieves potentially sensitive information from Grafana-backed datasources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal