redis-inspect

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a Node.js script (query.mjs) to perform various Redis operations such as get, keys, ttl, and info. This allows the agent to interact directly with infrastructure components.\n- [DATA_EXFILTRATION]: The skill is designed to read sensitive infrastructure data (sessions, feature flags, system configuration) from Redis and provide it to the agent's context. It also retrieves Redis connection credentials from .env files located in the skill directory or project root. While intended for debugging, this provides the agent with access to sensitive environment information.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from an external source (Redis) which could contain malicious instructions designed to influence the agent's behavior.\n
  • Ingestion points: Data is retrieved from Redis via commands implemented in query.mjs such as get, hgetall, smembers, and lrange.\n
  • Boundary markers: The skill does not use delimiters or explicit instructions to prevent the agent from following directions found within the cached data.\n
  • Capability inventory: The skill includes a del command in query.mjs which allows for data modification/deletion when the --writable flag is used, providing a mechanism for an indirect injection to trigger state changes.\n
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from Redis before it is added to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 05:08 AM
Security Audit — agent-trust-hub — redis-inspect