key-management-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and metadata are focused on providing a structured interface for key management and do not include any executable scripts or signs of malicious intent.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to the handling of metadata from external services.
  • Ingestion points: Data retrieved from KMS provider APIs and user-supplied configuration objects in the input schema.
  • Boundary markers: No specific instructions or delimiters are provided to ensure the agent ignores instructions potentially embedded in external key descriptions or metadata.
  • Capability inventory: The skill is configured to use tools including Bash, Read, Write, and WebFetch.
  • Sanitization: No logic is provided to sanitize or validate external content before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:58 AM
Security Audit — agent-trust-hub — key-management-orchestrator