package-spec

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to review integration package files such as manifests, changelogs, and Handlebars templates. This constitutes an ingestion surface for potentially untrusted data. However, the skill does not grant the agent dangerous capabilities like arbitrary code execution or network exfiltration based on this data.
  • Ingestion points: manifest.yml, changelog.yml, and agent stream templates (*.yml.hbs).
  • Capability inventory: The skill is primarily reference-based and does not include scripts or subprocess commands.
  • Boundary markers: None explicitly defined.
  • Sanitization: Not applicable to these instructional guidelines.
  • [EXTERNAL_DOWNLOADS]: The skill references and links to official Elastic GitHub repositories for package specifications and integration examples. It also references AWS CloudFormation templates hosted on official Elastic S3 buckets for Federated Identity setup. These are established vendor resources used for legitimate development tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:00 PM
Security Audit — agent-trust-hub — package-spec