skills/ericrisco/rsc-harness/redis/Gen Agent Trust Hub

redis

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a local shell script, scripts/verify.sh, which performs static analysis on the user's project directory. The script uses standard utilities (find and grep) to search for problematic Redis patterns in source code and configuration files. It is read-only, excludes sensitive directories like .git and node_modules, and does not perform network operations.
  • [DYNAMIC_EXECUTION]: The documentation includes optimized Lua script templates designed to be executed via the Redis EVAL command. These scripts are provided to ensure atomicity for complex operations such as distributed lock release and sliding-window rate limiting, following industry best practices for Redis security and reliability.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it is intended to ingest and analyze untrusted project source code provided by the user to offer optimization advice.
  • Ingestion points: Local source files in common programming languages (.js, .py, .go, etc.) identified by scripts/verify.sh and processed by the agent.
  • Boundary markers: The instructions do not define specific delimiters for the source code data, though the verify.sh script filters for specific Redis-related keywords.
  • Capability inventory: The skill utilizes local file system traversal and text searching via find and grep within the provided script.
  • Sanitization: None; the diagnostic script processes raw text content to identify specific command patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — redis