cel-programs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the creation of CEL programs for data collection from external APIs, creating a potential surface for indirect prompt injection. The risk is managed by instructions to sanitize data using encode_json() and encapsulate the raw content within a "message" field, preventing ingested data from being interpreted as instructions by the agent. Evidence: SKILL.md (Event output format section).
  • [COMMAND_EXECUTION]: The skill includes instructions for using command-line tools such as mito, stream, and elastic-package. These are official development utilities provided by the authoring vendor, Elastic, used to validate and package integrations. Evidence: references/mito-reference.md (Installation section).
  • [EXTERNAL_DOWNLOADS]: The instructions reference downloads from the author's official GitHub repositories and container registries for necessary development tooling. These references are limited to verified vendor infrastructure. Evidence: references/mito-reference.md (github.com/elastic/mito).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:03 PM
Security Audit — agent-trust-hub — cel-programs