Back to plugin

Security audit

Monitoring AIops

Security checks for vulnerabilities and agentic risk

Overview

The plugin fits its monitoring purpose, but it can make high-impact changes to monitoring systems and its MCP path lacks a built-in approval prompt.

Install only with monitoring accounts scoped to the access you are willing to grant. For observe-only use, use read-only SolarWinds, PRTG, or Zabbix credentials because the plugin itself says it has no read-only switch or authorization gate. Treat MCP write tools such as remove_node, unmanage_node, mute or maintenance actions, and Zabbix maintenance deletion as change-controlled operations requiring explicit user approval outside the tool.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/monitoring-aiops/references/agent-guardrails.md:42
Evidence
Copy this into your agent's system prompt: