managing-rabbitmq

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands using rabbitmqctl to gather cluster status, virtual hosts, and resource lists. This is consistent with the skill's stated administrative purpose.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to interact with the RabbitMQ Management API. While it defaults to localhost, the host is configurable, making it a network operation that could target non-whitelisted domains.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by ingesting and processing untrusted data (such as queue names, exchange names, and vhost names) from the RabbitMQ cluster and using it in subsequent shell command templates.
  • Ingestion points: Cluster resource metadata retrieved via rabbitmqctl and Management API calls in SKILL.md.
  • Boundary markers: Absent; the skill relies on standard shell quoting within its command templates but does not implement specific data delimiters.
  • Capability inventory: Execution of shell commands via rabbitmqctl and network requests via curl as defined in the helper functions.
  • Sanitization: Relies on jq for parsing JSON responses but lacks explicit sanitization or validation of resource names before they are interpolated into command strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:22 PM
Security Audit — agent-trust-hub — managing-rabbitmq