kafka-consumer-lag

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (Kafka topics) which presents an attack surface for indirect prompt injection.
  • Ingestion points: The mcp__Lenses__execute_sql tool is used in Step 4 to sample recent messages from Kafka topics (SELECT * FROM {topic} LIMIT 5).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potential instructions embedded within the sampled Kafka messages.
  • Capability inventory: The skill has access to file system tools (Read, Grep, Glob, Bash) and various Kafka management tools through the Lenses MCP server.
  • Sanitization: No specific sanitization or validation of the message content is mentioned before the agent processes it for reporting.
  • Risk Assessment: While the skill ingests external data, its purpose is purely diagnostic and reporting-oriented, with no instructions to execute actions based on message content. This represents a standard risk surface for data-processing skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:45 PM
Security Audit — agent-trust-hub — kafka-consumer-lag