grafana — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited grafana (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Query and manage Grafana monitoring dashboards, alert rules, and data sources via HTTP API.
Configure your Grafana instance:
| Variable | Description | Required |
|---|---|---|
GRAFANA_URL | Your Grafana server URL (e.g., https://grafana.example.com) | Yes |
GRAFANA_TOKEN | API Key (Settings → API Keys, viewer or editor role) | Yes |
Authentication: curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" "$GRAFANA_URL/api/..."
Customize the following for your organization:
{Service} {Metric} {Condition} [{env}])Find a Dashboard:
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/search?query=<keyword>&tag=<tag>&type=dash-db" \
| jq '.[] | {uid, title, folderTitle}'Get Dashboard Details:
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/dashboards/uid/<uid>" \
| jq '.dashboard.panels[] | {title, type}'Check Active Alerts:
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/alerts?state=alerting"List Data Sources:
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/datasources" \
| jq '.[] | {id, name, type, url}'Search by Folder:
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/search?folderIds=<folder_id>&type=dash-db"After each deployment, check key dashboards for:
GET /api/alerts?state=alerting — list all firing alerts# Delete a production dashboard (never delete, archive instead)
curl -X DELETE "$GRAFANA_URL/api/dashboards/uid/abc123"
# Fetch all dashboards without filtering (use search first)
for uid in $(curl ... /api/search | jq -r '.[].uid'); do
curl ... /api/dashboards/uid/$uid
done# Search dashboards by tag
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/search?tag=production&type=dash-db" \
| jq '.[] | {uid, title, folderTitle}'
# Check active alerts
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/alerts?state=alerting"
# Get alert details for troubleshooting
curl -s -H "Authorization: Bearer $GRAFANA_TOKEN" \
"$GRAFANA_URL/api/alerts/<alert_id>"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.