kafka-perf-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of potentially untrusted data from codebase files and cluster configurations, creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads local codebase files using Grep, Glob, and Read tools, and it fetches live cluster configurations via the Lenses MCP server tools.
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to ensure that data fetched from these sources is treated as non-executable content or to ignore any embedded instructions.
- Capability inventory: The skill is configured with access to powerful capabilities including the Bash tool and direct file system access, which could be exploited if an indirect prompt injection attack were successful.
- Sanitization: The workflow does not include any steps to sanitize, validate, or filter the content retrieved from the codebase or the cluster before it is processed by the agent's core analysis logic.
Audit Metadata