kanidm-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain any malicious patterns. It focuses entirely on providing expert guidance for the Kanidm identity management system.
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for managing identity infrastructure. These include server configuration (kanidmd), user/group management (kanidm), and system integration tasks (configuring sshd, PAM modules, and sudo). All commands are standard for identity management operations.
  • [EXTERNAL_DOWNLOADS]: The documentation references the installation of standard system packages using apt, dnf, and brew. It also references well-known Python libraries like httpx, pytest, and ldap3. These installations target official package registries and repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes patterns for ingesting data from external sources such as the Kanidm REST API and LDAP directories. While this presents a surface for indirect prompt injection if the external data is maliciously crafted, the skill demonstrates secure practices, such as using ldap3.utils.conv.escape_filter_chars to sanitize inputs in LDAP queries.
  • Ingestion points: REST API responses (via httpx) and LDAP search results (via ldap3) in SKILL.md and references/integration-guide.md.
  • Boundary markers: Generally absent in the provided code templates.
  • Capability inventory: Network requests via httpx, LDAP operations via ldap3, and local shell execution via the kanidm CLI tools.
  • Sanitization: The skill explicitly recommends and provides examples of escaping LDAP filter characters to prevent injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — kanidm-expert