mosquitto-clients
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands using
mosquitto_pubandmosquitto_subto interact with MQTT brokers. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by facilitating the ingestion of untrusted data from external MQTT brokers.
- Ingestion points: The output of the
mosquitto_subcommand which reads message streams from network brokers. - Boundary markers: The instructions do not define delimiters or specific warnings for the agent to ignore instructions embedded in message payloads.
- Capability inventory: The skill permits subprocess execution of the
mosquitto_pubandmosquitto_subCLI tools. - Sanitization: No sanitization, filtering, or validation of incoming MQTT message content is specified.
Audit Metadata