Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md ADOG_API_KEY"],"bins":["curl","jq"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"📡"}}
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a monitoring guide, but it encourages automated restarts, rollbacks, remote SSH commands, and long-running deployment without enough scoping or confirmation safeguards.
Install only if you are comfortable letting an agent help configure monitoring tied to alerting and infrastructure actions. Keep restart, rollback, AWS, SSH, and webhook actions disabled unless each target and command is explicitly approved, scoped, logged, and reversible. Use least-privilege API keys and never paste real bearer tokens directly into prompts or shared configs.
Referenced artifact was not completely inspected
ADOG_API_KEY"],"bins":["curl","jq"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"📡"}}
The skill advertises automatic restart, rollback, webhook triggering, and remote SSH command execution without requiring explicit user confirmation or providing strong safety guardrails. In an agent context, these capabilities can lead to destructive changes, service disruption, or unintended infrastructure actions if triggered from ambiguous prompts or misconfigured monitors.
The manifest description says to use the skill when the user needs "uptime tracking, performance monitoring, or automated incident response across multiple domains," which describes a wide class of common requests rather than narrow trigger phrases or constraints. Because no exclusion conditions or negative examples are provided in the manifest, the activation scope is ambiguous and may cause unintended invocation collisions with other ops or monitoring skills.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Monitor these sites every 5 minutes and alert Slack if any fail:
- https://api.example.com/health
- https://app.example.com/status
- https://cdn.example.com/ping
- https://wordpress.example.com/wp-json/health
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Monitor these sites every 5 minutes and alert Slack if any fail:
- https://api.example.com/health
- https://app.example.com/status
- https://cdn.example.com/ping
- https://wordpress.example.com/wp-json/health
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Monitor these sites every 5 minutes and alert Slack if any fail:
- https://api.example.com/health
- https://app.example.com/status
- https://cdn.example.com/ping
- https://wordpress.example.com/wp-json/health
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Monitor these sites every 5 minutes and alert Slack if any fail:
- https://api.example.com/health
- https://app.example.com/status
- https://cdn.example.com/ping
- https://wordpress.example.com/wp-json/health
This example includes an Authorization header with a bearer token in outbound requests, normalizing the use of sensitive credentials in monitoring probes. In an agent setting, this increases the risk of secret exposure through logs, prompt leakage, copied examples, or transmission to misconfigured/untrusted endpoints.
Example: Monitor API health with custom authentication
Endpoint: https://api.example.com/health
Method: POST
Headers:
Authorization: Bearer YOUR_API_KEY
No suspicious patterns detected.