kibana-anomaly-detection
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process raw log data from external sources via tools such as
ad_rca_source_evidenceandad_search_log_category_examples. These ingestion points represent a surface for indirect prompt injection where malicious content in the logs could attempt to influence the agent's reasoning. The skill lacks explicit boundary markers or sanitization instructions for the agent when handling these raw outputs. - Evidence: Found in
references/kibana/tools/esql/ad_rca_source_evidence.jsonandreferences/kibana/tools/esql/ad_search_log_category_examples.json. - Capabilities: The agent has the ability to create and modify machine learning jobs and datafeeds, which increases the potential impact of an injection attack.
- [DYNAMIC_EXECUTION]: The workflow
ad_wf_ts_field_cardinality.yamluses Liquid templates to dynamically interpolate thesplit_field_esqlinput directly into the text of an ES|QL query. This creates a potential injection surface if the input is not strictly sourced from the existing job configuration as intended. - Evidence: File
references/kibana/workflows/ad_wf_ts_field_cardinality.yamlcontains:query: "FROM * METADATA _index | ... | STATS distinct_count = COUNT_DISTINCT({{ inputs.split_field_esql }}) | LIMIT 1". - [CREDENTIALS_UNSAFE]: The registration script
scripts/kibana-agent-builder.mjsand thereferences/README.mddocumentation contain hardcoded default credentials (elastic/changeme). These are well-known defaults for local Elastic Stack development environments. The skill correctly identifies and recommends the use of environment-based configuration for API keys and tokens in production environments.
Audit Metadata