konnect-api-publish
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses established Kong and Konnect management tools (kongctl, terraform, deck) for their intended administrative purposes.- [SAFE]: No hardcoded credentials, malicious network operations, or obfuscation techniques were found in the instructions or reference files.- [PROMPT_INJECTION]: The skill presents a theoretical indirect prompt injection surface common to infrastructure management agents. It processes tool outputs (managed API state, catalog metadata) and has mutation capabilities. (1) Ingestion points:
kong-konnectMCP andkongctl-queryoutputs. (2) Boundary markers: None explicitly defined. (3) Capability inventory: Infrastructure modification viakongctl-declarative,terraform-konnect, anddeck-gateway. (4) Sanitization: No explicit validation steps for external content. This surface is considered a standard operational risk for this use case and does not reflect a specific vulnerability.
Audit Metadata