keeper-admin

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the 'keeper' CLI for administrative operations. It includes a specific workflow in the enterprise management reference that generates and executes a Python script via a shell heredoc to process local JSON data and produce compliance reports. Additionally, it supports running a local REST API server on a configurable port.- [DATA_EXFILTRATION]: The skill provides commands for bulk exporting vault records and audit logs to the local file system in JSON and CSV formats. While these are intended administrative features, they represent a mechanism for transferring sensitive data out of the secure vault environment.- [PROMPT_INJECTION]: The skill ingests untrusted data from vault records and external import files. This creates an indirect prompt injection surface where malicious instructions embedded in vault metadata or records could influence the agent's logic when processing that data. The skill includes specific guardrails to prevent printing secrets directly into the chat context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 01:46 PM