elastic-package-cli

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides documentation and workflow guidance for the elastic-package CLI. It does not include any scripts, executables, or code files, which minimizes the attack surface to purely informational content.- [COMMAND_EXECUTION]: The skill documents standard usage of the elastic-package tool for tasks like formatting, linting, building, and testing integrations (e.g., elastic-package check, elastic-package stack up). These commands are typical for the described development context and do not attempt to execute arbitrary or dangerous shell commands.- [EXTERNAL_DOWNLOADS]: The skill references the elastic-package tool. As an official resource from Elastic (a well-known vendor), this reference is considered safe and does not trigger a verdict escalation.- [INDIRECT_PROMPT_INJECTION]: While the skill describes workflows that ingest integration package data, it does not demonstrate exploitable patterns or encourage the processing of untrusted content in a way that would bypass agent safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:03 PM
Security Audit — agent-trust-hub — elastic-package-cli