kafka-schema-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from several external and local sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: Data is ingested from the live Kafka cluster using tools like mcp__Lenses__list_topic_metadata, mcp__Lenses__get_topic_metadata, and mcp__Lenses__execute_sql (which samples live messages). It also reads local schema definition files (.avsc, .proto, .json) and searches codebase contents using Read, Grep, and Glob.
  • Boundary markers: The instructions do not define explicit boundary markers or instructions for the agent to ignore potentially malicious content embedded within the schema metadata or sampled message data.
  • Capability inventory: The skill has access to Bash for repository inspection (e.g., git diff) and can perform SQL executions on the Kafka cluster, which could be misused if the agent is manipulated by injected instructions.
  • Sanitization: There are no specified sanitization or validation steps for the external content before it is analyzed by the agent, relying entirely on the underlying model's guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:45 PM
Security Audit — agent-trust-hub — kafka-schema-review