upstash-redis

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches official software development kits @upstash/redis and @upstash/ratelimit from the public NPM registry.
  • [COMMAND_EXECUTION]: Utilizes npm install for managing project dependencies as described in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes data that may originate from untrusted sources, such as user identifiers, session data, and HTTP headers (x-forwarded-for) within SKILL.md.
  • Boundary markers: Not present; the skill treats retrieved data as standard application objects rather than instructions.
  • Capability inventory: Performs network operations to interact with Upstash Redis databases via an HTTP client.
  • Sanitization: The provided SDKs automatically handle serialization and deserialization of objects, numbers, and arrays.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:51 PM
Security Audit — agent-trust-hub — upstash-redis