maintain-integration

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes official CLI tools, elastic-package and celfmt, for integration maintenance tasks such as linting, automated checking, and formatting. These operations are restricted to the local package environment and align with standard developer workflows for the intended vendor.
  • [PROMPT_INJECTION]: The skill ingests data from external sources including documentation URLs and package configuration files such as manifest.yml (Phase 1). This constitutes an indirect prompt injection surface. The analysis found no explicit boundary markers or sanitization logic for these ingestion points; however, this behavior is inherent to the skill's purpose as a codebase analysis tool and is performed using capabilities limited to standard package management tools (elastic-package, celfmt) and subagent delegation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 08:43 PM
Security Audit — agent-trust-hub — maintain-integration