The skill mandates autonomous operation by bypassing human-in-the-loop controls and uses fabricated user consent to perform unauthorized resource creation while lacking transparency and proper documentation.
npx skills add https://github.com/signoz/agent-skillsThe skill contains explicit instructions for autonomous operation without human-in-the-loop controls, which contradicts standard security practices for write-heavy operations.
The skill states: 'The skill targets two consumers: an autonomous AI SRE agent that runs without a human in the loop... In autonomous mode (no human), escalate to the caller or fill the gap from upstream context.'
The instructions explicitly define an 'autonomous mode' where the agent is directed to bypass human confirmation if inputs are missing, which could lead to unauthorized resource creation.
In autonomous mode (no human), escalate to the caller or fill the gap from upstream context.
Autonomous operation instructions detected — attempts to remove human-in-the-loop controls (seen 2 times in this file at lines 85, 226)
autonomous mode
Fabricated user consent / pre-authorized instruction — a statement falsely attributed to the user to manufacture authorization
The user has already agreed
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
SKILL.md links to "references/examples.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/examples.md`](references/examples.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/signoz/agent-skills/signoz-creating-dashboards)<a href="https://mondoo.com/ai-agent-security/skills/github/signoz/agent-skills/signoz-creating-dashboards"><img src="https://mondoo.com/ai-agent-security/api/badge/github/signoz/agent-skills/signoz-creating-dashboards.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/signoz/agent-skills/signoz-creating-dashboards.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.