kibana-anomaly-detection

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process raw log data from external sources via tools such as ad_rca_source_evidence and ad_search_log_category_examples. These ingestion points represent a surface for indirect prompt injection where malicious content in the logs could attempt to influence the agent's reasoning. The skill lacks explicit boundary markers or sanitization instructions for the agent when handling these raw outputs.
  • Evidence: Found in references/kibana/tools/esql/ad_rca_source_evidence.json and references/kibana/tools/esql/ad_search_log_category_examples.json.
  • Capabilities: The agent has the ability to create and modify machine learning jobs and datafeeds, which increases the potential impact of an injection attack.
  • [DYNAMIC_EXECUTION]: The workflow ad_wf_ts_field_cardinality.yaml uses Liquid templates to dynamically interpolate the split_field_esql input directly into the text of an ES|QL query. This creates a potential injection surface if the input is not strictly sourced from the existing job configuration as intended.
  • Evidence: File references/kibana/workflows/ad_wf_ts_field_cardinality.yaml contains: query: "FROM * METADATA _index | ... | STATS distinct_count = COUNT_DISTINCT({{ inputs.split_field_esql }}) | LIMIT 1".
  • [CREDENTIALS_UNSAFE]: The registration script scripts/kibana-agent-builder.mjs and the references/README.md documentation contain hardcoded default credentials (elastic/changeme). These are well-known defaults for local Elastic Stack development environments. The skill correctly identifies and recommends the use of environment-based configuration for API keys and tokens in production environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:14 AM
Security Audit — agent-trust-hub — kibana-anomaly-detection