managing-rabbitmq
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands using
rabbitmqctlto gather cluster status, virtual hosts, and resource lists. This is consistent with the skill's stated administrative purpose. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto interact with the RabbitMQ Management API. While it defaults to localhost, the host is configurable, making it a network operation that could target non-whitelisted domains. - [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by ingesting and processing untrusted data (such as queue names, exchange names, and vhost names) from the RabbitMQ cluster and using it in subsequent shell command templates.
- Ingestion points: Cluster resource metadata retrieved via
rabbitmqctland Management API calls in SKILL.md. - Boundary markers: Absent; the skill relies on standard shell quoting within its command templates but does not implement specific data delimiters.
- Capability inventory: Execution of shell commands via
rabbitmqctland network requests viacurlas defined in the helper functions. - Sanitization: Relies on
jqfor parsing JSON responses but lacks explicit sanitization or validation of resource names before they are interpolated into command strings.
Audit Metadata