event-driven-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides implementation patterns for event consumers that ingest and process data from external message brokers, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: The
eachMessagehandler inSKILL.md(Pattern 2) and themonitorDLQfunction inSKILL.md(Pattern 4) process JSON payloads received from Kafka topics and SQS queues respectively. - Boundary markers: The example code snippets do not implement specific delimiters or instructions to the agent to disregard natural language commands that might be embedded within the event payloads.
- Capability inventory: The skill defines consumers with capabilities to perform database operations (via Prisma), execute cross-service saga orchestration steps, and interact with message broker APIs (KafkaJS, AWS SQS SDK).
- Sanitization: While the skill uses
JSON.parseto handle message bodies, it does not demonstrate content validation or sanitization strategies to prevent the interpretation of data fields as instructions.
Audit Metadata