review-integration
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting untrusted data (user-provided package names and file lists) and incorporating them into shell commands.
- Ingestion points: The user-provided package directory path and changed file list are used in shell commands like
cdandelastic-packageinSKILL.mdStep 5. - Boundary markers: The instructions do not specify boundary markers or delimiters to encapsulate untrusted user inputs when they are passed to the shell.
- Capability inventory: The skill uses shell execution capabilities to run
elastic-package format,lint, andcheck(SKILL.md). - Sanitization: No explicit sanitization or validation logic for user-provided paths is defined, creating a surface for command injection.
- [COMMAND_EXECUTION]: The skill executes the
elastic-packageCLI tool to validate integration artifacts. This is a standard and documented part of the vendor's workflow.
Audit Metadata