kafka-schema-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from several external and local sources, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: Data is ingested from the live Kafka cluster using tools like
mcp__Lenses__list_topic_metadata,mcp__Lenses__get_topic_metadata, andmcp__Lenses__execute_sql(which samples live messages). It also reads local schema definition files (.avsc, .proto, .json) and searches codebase contents usingRead,Grep, andGlob. - Boundary markers: The instructions do not define explicit boundary markers or instructions for the agent to ignore potentially malicious content embedded within the schema metadata or sampled message data.
- Capability inventory: The skill has access to
Bashfor repository inspection (e.g.,git diff) and can perform SQL executions on the Kafka cluster, which could be misused if the agent is manipulated by injected instructions. - Sanitization: There are no specified sanitization or validation steps for the external content before it is analyzed by the agent, relying entirely on the underlying model's guardrails.
Audit Metadata