elasticsearch

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill does not contain any executable scripts or shell commands. It exclusively provides configuration examples and architectural guidelines.
  • [DATA_EXFILTRATION]: The instructions explicitly warn against exposing clusters to the internet and mandate that credentials and queries must remain on the server side to prevent data leaks.
  • [PROMPT_INJECTION]: The content focuses on technical documentation and best practices. There are no instructions that attempt to override AI safety filters or hijack agent behavior.
  • [REMOTE_CODE_EXECUTION]: No remote downloads or dynamic code execution patterns are present. It recommends using official clients for various programming languages.
  • [INDIRECT_PROMPT_INJECTION]: The skill lacks data ingestion surfaces that could be exploited by external untrusted content. It focuses on how an agent should assist a developer in writing Elasticsearch queries and mappings.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets or API keys are present. The documentation advises proper credential management by keeping them server-side.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:04 PM
Security Audit — agent-trust-hub — elasticsearch