elasticsearch-authz
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlto interact with Elasticsearch and Kibana security APIs for user, role, and role mapping management. This is the primary and expected function of the skill. - [PROMPT_INJECTION]: The skill features a natural language decomposition workflow that translates user requests into security configurations, presenting a surface for indirect prompt injection.
- Ingestion points: Natural language access requests processed in
SKILL.md. - Boundary markers: Not present.
- Capability inventory: Administrative API access via
curlas defined inSKILL.mdandreferences/api-reference.md. - Sanitization: The skill provides guidance for generating strong passwords but does not specify sanitization for other user-controlled strings like role names or query filters.
Audit Metadata