managing-keycloak
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses standard utilities like curl and jq to interact with the Keycloak administrative API. These commands are legitimate and aligned with the intended purpose of auditing and managing identity realms.\n- [DATA_EXFILTRATION]: All network requests are directed to the user-controlled KC_BASE_URL. No patterns of unauthorized data transmission or connections to third-party services were observed.\n- [CREDENTIALS_UNSAFE]: Handles authentication through environment variables and includes specific logic to mask sensitive data such as client secrets and LDAP bind credentials, ensuring they are not exposed in reports.
Audit Metadata