msk-migration

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is assessment and planning for AWS MSK migrations. All external resources (GitHub repositories, documentation URLs) belong to the skill author (confluentinc) or trusted organizations like AWS and the Confluent documentation site.
  • [COMMAND_EXECUTION]: The skill uses the kcp CLI (Confluent's open-source migration tool). Command execution follows safety principles: mandatory user approval for mutating commands, read-only parsing for user-provided files, and batch-prevention to avoid compound shell injection vulnerabilities. These patterns are standard for developer-centric assistant skills.
  • [EXTERNAL_DOWNLOADS]: References and fetch operations target official Confluent documentation (docs.confluent.io) and the official KCP GitHub repository (confluentinc/kcp). Per internal guidelines, these well-known vendor resources are treated as safe.
  • [CREDENTIALS_UNSAFE]: The skill includes explicit invariants and instructions (Invariant #9) never to display or log credentials, API keys, or secret environment variables. It instructs users on safe secret management using credential files without embedding them in the prompt context.
  • [PROMPT_INJECTION]: No evidence of malicious override or bypass attempts was found. The skill includes standard instructional language to guide the AI's role as a migration assistant.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 05:07 AM
Security Audit — agent-trust-hub — msk-migration