Back to plugin

Security audit

Observability AIops

Security checks for vulnerabilities and agentic risk

Overview

This plugin matches its stated observability purpose, but users should use least-privilege credentials because it can silence alerts and change dashboards when granted write access.

Install this only for agents you intend to use against a self-hosted observability stack. Start with read-only or viewer-scoped credentials, protect the OBSERVABILITY_AIOPS_MASTER_PASSWORD value, and require an explicit operator go-ahead before enabling or using write-scoped actions such as alert silences, dashboard deletion, or Prometheus reloads.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/observability-aiops/references/agent-guardrails.md:31
Evidence
Copy this into your agent's system prompt: