elastic-package-cli
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides documentation and workflow guidance for the
elastic-packageCLI. It does not include any scripts, executables, or code files, which minimizes the attack surface to purely informational content.- [COMMAND_EXECUTION]: The skill documents standard usage of theelastic-packagetool for tasks like formatting, linting, building, and testing integrations (e.g.,elastic-package check,elastic-package stack up). These commands are typical for the described development context and do not attempt to execute arbitrary or dangerous shell commands.- [EXTERNAL_DOWNLOADS]: The skill references theelastic-packagetool. As an official resource from Elastic (a well-known vendor), this reference is considered safe and does not trigger a verdict escalation.- [INDIRECT_PROMPT_INJECTION]: While the skill describes workflows that ingest integration package data, it does not demonstrate exploitable patterns or encourage the processing of untrusted content in a way that would bypass agent safety guardrails.
Audit Metadata