cx-platform-admin
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
cxCLI tool to perform administrative tasks within the Coralogix platform. These operations include listing, creating, updating, and deleting sensitive IAM resources such as API keys, users, and roles. - [INDIRECT_PROMPT_INJECTION]: The skill represents a potential surface for indirect prompt injection due to its ingestion of untrusted data.
- Ingestion points: Data enters the agent context through commands like
cx iam users search,cx iam roles list, andcx iam groups list, which retrieve user-controlled fields (e.g., usernames, group names, role descriptions). - Boundary markers: None explicitly defined in the provided commands, although the skill instructions mandate manual confirmation before write actions.
- Capability inventory: The skill has the capability to perform destructive write operations (delete keys, deactivate users, modify IP rules) and read sensitive credentials (API keys).
- Sanitization: There is no explicit evidence of sanitization or filtering of the retrieved IAM data before it is processed by the agent.
- [SAFE]: The skill is a legitimate administrative tool provided for the Coralogix platform. The capabilities described align with its stated purpose of platform administration. All sensitive and destructive operations are gated by explicit instructions to seek user confirmation and avoid the
--yesflag unless approved.
Audit Metadata