mosquitto-clients

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands using mosquitto_pub and mosquitto_sub to interact with MQTT brokers.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by facilitating the ingestion of untrusted data from external MQTT brokers.
  • Ingestion points: The output of the mosquitto_sub command which reads message streams from network brokers.
  • Boundary markers: The instructions do not define delimiters or specific warnings for the agent to ignore instructions embedded in message payloads.
  • Capability inventory: The skill permits subprocess execution of the mosquitto_pub and mosquitto_sub CLI tools.
  • Sanitization: No sanitization, filtering, or validation of incoming MQTT message content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — mosquitto-clients