skills/joaoseidel/ktor-toolkit/cache/Gen Agent Trust Hub

cache

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional, providing best practices for using standard caching libraries (Ktor, Lettuce/Redis). It does not contain executable scripts, hidden commands, or external dependencies outside of well-known software ecosystems.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill mentions processing sensitive data such as authentication headers and tenant IDs, it does so to warn developers against common misconfigurations that lead to data leakage between clients. It provides clear remediation steps, such as including distinguishing values in the cache namespace.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture that ingests untrusted data (HTTP request parameters and headers) to generate cache keys. It includes mandatory guidance for developers to sanitize this process by excluding non-functional parameters (like trace IDs) and using appropriate boundary markers in namespaces to prevent key collisions or unauthorized data access.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:58 PM
Security Audit — agent-trust-hub — cache