konnect-api-publish

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses established Kong and Konnect management tools (kongctl, terraform, deck) for their intended administrative purposes.- [SAFE]: No hardcoded credentials, malicious network operations, or obfuscation techniques were found in the instructions or reference files.- [PROMPT_INJECTION]: The skill presents a theoretical indirect prompt injection surface common to infrastructure management agents. It processes tool outputs (managed API state, catalog metadata) and has mutation capabilities. (1) Ingestion points: kong-konnect MCP and kongctl-query outputs. (2) Boundary markers: None explicitly defined. (3) Capability inventory: Infrastructure modification via kongctl-declarative, terraform-konnect, and deck-gateway. (4) Sanitization: No explicit validation steps for external content. This surface is considered a standard operational risk for this use case and does not reflect a specific vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:45 PM
Security Audit — agent-trust-hub — konnect-api-publish