redis-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Data is retrieved from Redis via r.get(), r.hgetall(), and pubsub.listen() in SKILL.md.\n
  • Boundary markers: No specific delimiters or "ignore" instructions are used when handling data retrieved from Redis.\n
  • Capability inventory: The skill uses the redis Python client to perform read, write, and delete operations, and executes Lua scripts.\n
  • Sanitization: The provided code snippets do not implement sanitization or validation of the data retrieved from Redis before returning it to the agent's context.\n- [DYNAMIC_EXECUTION]: The skill uses Redis Lua scripting to ensure atomicity for complex operations.\n
  • Evidence: Lua scripts are defined as static strings and executed via r.eval() in the acquire_token and release_lock functions in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — redis-patterns