cel-programs

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the mito and stream CLI tools directly from Elastic's official GitHub repositories (github.com/elastic/mito and github.com/elastic/stream).
  • [COMMAND_EXECUTION]: The workflow involves executing local development commands using tools like mito, stream, and elastic-package to validate CEL expressions and run system tests against local mock environments.
  • [REMOTE_CODE_EXECUTION]: The skill is centered on the creation of CEL programs which are dynamically evaluated by the Elastic Agent to perform data collection. This is the core functionality of the skill, and the provided documentation (e.g., references/cel-code-style.md) mandates strict structural and safety standards for these expressions.
  • [SAFE]: The skill incorporates security best practices, including mandatory redaction of sensitive state keys via the redact.fields configuration and a strict data anonymization policy for all data committed to repositories (as detailed in SKILL.md under Data anonymization).
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 08:43 PM
Security Audit — agent-trust-hub — cel-programs