managing-redis-deep

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines and executes bash scripts to automate Redis administrative tasks. It invokes the redis-cli tool to retrieve server metadata, cluster topology, and memory metrics.
  • [DATA_EXFILTRATION]: The skill accesses sensitive internal configuration data including Access Control Lists (ACLs) and connected client metadata. This information is exposed to the agent for diagnostic purposes.
  • [PROMPT_INJECTION]: The skill processes untrusted data from the Redis server which could facilitate indirect prompt injection. 1. Ingestion points: Redis command output (Phase 1 and Phase 2 discovery in SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via bash scripts. 4. Sanitization: Absent. This creates an attack surface where instructions embedded in Redis keys or metadata could influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-redis-deep