event-driven-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides implementation patterns for event consumers that ingest and process data from external message brokers, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: The eachMessage handler in SKILL.md (Pattern 2) and the monitorDLQ function in SKILL.md (Pattern 4) process JSON payloads received from Kafka topics and SQS queues respectively.
  • Boundary markers: The example code snippets do not implement specific delimiters or instructions to the agent to disregard natural language commands that might be embedded within the event payloads.
  • Capability inventory: The skill defines consumers with capabilities to perform database operations (via Prisma), execute cross-service saga orchestration steps, and interact with message broker APIs (KafkaJS, AWS SQS SDK).
  • Sanitization: While the skill uses JSON.parse to handle message bodies, it does not demonstrate content validation or sanitization strategies to prevent the interpretation of data fields as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 03:48 AM
Security Audit — agent-trust-hub — event-driven-architecture