managing-redis-deep
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines and executes bash scripts to automate Redis administrative tasks. It invokes the redis-cli tool to retrieve server metadata, cluster topology, and memory metrics.
- [DATA_EXFILTRATION]: The skill accesses sensitive internal configuration data including Access Control Lists (ACLs) and connected client metadata. This information is exposed to the agent for diagnostic purposes.
- [PROMPT_INJECTION]: The skill processes untrusted data from the Redis server which could facilitate indirect prompt injection. 1. Ingestion points: Redis command output (Phase 1 and Phase 2 discovery in SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via bash scripts. 4. Sanitization: Absent. This creates an attack surface where instructions embedded in Redis keys or metadata could influence agent behavior.
Audit Metadata