kafka-connector-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes Kafka connector configurations, which act as an external and potentially untrusted data source.
  • Ingestion points: Connector definitions are fetched using the mcp__Lenses__get_kafka_connector_target_definition tool as described in SKILL.md.
  • Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from following instructions that might be embedded within the configuration data.
  • Capability inventory: The agent environment includes high-capability tools such as Bash, Read, Grep, and Glob as specified in the allowed-tools frontmatter.
  • Sanitization: The skill does not implement content validation or sanitization for the retrieved configuration strings before processing them for audit report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:45 PM
Security Audit — agent-trust-hub — kafka-connector-review