dashboard-review

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions in 'SKILL.md' require the installation of the 'kbdash' utility using 'go install github.com/efd6/kbdash@latest'. This downloads and compiles code from a GitHub repository belonging to an individual user account ('efd6') rather than the official vendor ('elastic') or a trusted organization.
  • [COMMAND_EXECUTION]: The workflow defined in 'references/review-procedure.md' relies on the execution of shell commands such as 'gh pr diff', 'git diff', and 'git show' to automate the identification, extraction, and comparison of dashboard JSON files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes dashboard JSON files from external sources like pull requests, which could contain malicious content designed to influence the agent's behavior during the review process. 1. Ingestion points: Dashboard JSON files under '/kibana/dashboard/.json' are read and processed. 2. Boundary markers: Absent. No specific delimiters or safety instructions are provided to isolate the ingested JSON data from the agent's summary and analysis tasks. 3. Capability inventory: The skill utilizes shell access, git, and the third-party 'kbdash' executable. 4. Sanitization: Absent. The skill analyzes the output of 'kbdash' and the raw JSON without explicit validation or sanitization steps.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 04:00 PM
Security Audit — agent-trust-hub — dashboard-review