keycloak-client-onboarder
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified in the skill. The instructions provide a legitimate workflow for identity management and infrastructure provisioning.- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Service names and URI patterns are interpolated into the client configuration workflow.
- Ingestion points: Service names and ingress routes defined in Step 2.
- Boundary markers: Not present.
- Capability inventory: Creating and configuring Keycloak clients and retrieving secrets via keycloak-mcp.
- Sanitization: No explicit validation or sanitization is performed on user-supplied service names.
Audit Metadata