indykite-authzen-kbac-policies
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a utility script (
scripts/create-policy.sh) used to interact with the IndyKite Config API. The script implements security safeguards by pinning the target API host to official IndyKite domains (eu.api.indykite.comorus.api.indykite.com), preventing the accidental transmission of Service Account tokens to untrusted URLs. Additionally, the script's--printfunctionality is designed to redact theAuthorizationheader to prevent credential leakage in terminal logs.- [EXTERNAL_DOWNLOADS]: The skill facilitates network communication with the IndyKite regional REST APIs. These connections are necessary for the primary purpose of managing authorization policies and are restricted to the vendor's known infrastructure.- [PROMPT_INJECTION]: The instructions and references focus on technical configuration using Cypher queries for Knowledge-Based Access Control. No patterns were found that attempt to subvert agent behavior, bypass safety guidelines, or extract system prompts.
Audit Metadata