managing-redis

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell-based helper functions to execute redis-cli, python3, awk, and grep for server discovery, performance monitoring, and slow log analysis.
  • [CREDENTIALS_UNSAFE]: The implementation uses the -a flag with redis-cli to provide the database password. This approach can leak credentials to other system users through process monitoring tools like ps. The skill documentation explicitly flags this as a pitfall and suggests alternative environment variables.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks due to its data ingestion surface.
  • Ingestion points: Data retrieved from Redis (e.g., key names, configuration values, slow log entries, and client lists) enters the agent's context and is processed by scripts in SKILL.md.
  • Boundary markers: The skill does not employ specific delimiters or instructions to prevent the agent from being influenced by data returned from the Redis server.
  • Capability inventory: The skill has the capability to execute shell commands and Python code locally based on data processed from Redis.
  • Sanitization: There is no explicit sanitization of the values or keys retrieved from the database before they are used in scripts or presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-redis