entity-mappings

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides commands in SKILL.md and references/entity-field-catalog.md that fetch field availability metadata from the official Elastic ECS GitHub repository. These diagnostic commands parse CSV data from raw.githubusercontent.com/elastic/ecs/ using standard shell utilities like awk and cut to verify schema compatibility.
  • [INDIRECT_PROMPT_INJECTION]: The analysis workflow involves ingesting external data from integration package files and vendor API documentation for services such as AWS, GCP, and GitHub.
  • Ingestion points: The agent fetches and reads vendor documentation during the gap analysis process (documented in references/gap-analysis-workflow.md and references/analysis-subagent-guidance.md).
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters for external content, though they recommend a structured report template for findings.
  • Capability inventory: The skill uses subagent dispatch, local file reading, and network fetching of documentation.
  • Sanitization: Content from vendor documentation is analyzed for mapping purposes without specific secondary sanitization requirements, as it originates from well-known and reputable technical documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:53 AM
Security Audit — agent-trust-hub — entity-mappings