kafka-security-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external codebase files, including source code, configuration files, and CI/CD scripts, which are untrusted ingestion surfaces. Maliciously crafted content within these files could attempt to override agent instructions during the audit process.
  • Ingestion points: Codebase inspection using Read, Grep, and Glob tools across application directories (src/, app/, lib/), configuration folders, and environment files.
  • Boundary markers: The instructions do not define specific delimiters or prompts for the agent to ignore instructions embedded within the files being audited.
  • Capability inventory: The skill allows access to the Bash tool and various Lenses MCP tools, providing a significant capability surface if an injection is successful.
  • Sanitization: There is no evidence of sanitization or filtering of file content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill is configured with the Bash tool to perform environment checks (e.g., git status, file presence). While intended for audit purposes, this provides an execution environment that interacts with the results of the codebase scanning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:45 PM
Security Audit — agent-trust-hub — kafka-security-audit