kafka-connector-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes Kafka connector configurations, which act as an external and potentially untrusted data source.
- Ingestion points: Connector definitions are fetched using the
mcp__Lenses__get_kafka_connector_target_definitiontool as described inSKILL.md. - Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from following instructions that might be embedded within the configuration data.
- Capability inventory: The agent environment includes high-capability tools such as
Bash,Read,Grep, andGlobas specified in theallowed-toolsfrontmatter. - Sanitization: The skill does not implement content validation or sanitization for the retrieved configuration strings before processing them for audit report generation.
Audit Metadata