kanidm-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill does not contain any malicious patterns. It focuses entirely on providing expert guidance for the Kanidm identity management system.
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for managing identity infrastructure. These include server configuration (
kanidmd), user/group management (kanidm), and system integration tasks (configuringsshd, PAM modules, andsudo). All commands are standard for identity management operations. - [EXTERNAL_DOWNLOADS]: The documentation references the installation of standard system packages using
apt,dnf, andbrew. It also references well-known Python libraries likehttpx,pytest, andldap3. These installations target official package registries and repositories. - [INDIRECT_PROMPT_INJECTION]: The skill includes patterns for ingesting data from external sources such as the Kanidm REST API and LDAP directories. While this presents a surface for indirect prompt injection if the external data is maliciously crafted, the skill demonstrates secure practices, such as using
ldap3.utils.conv.escape_filter_charsto sanitize inputs in LDAP queries. - Ingestion points: REST API responses (via
httpx) and LDAP search results (vialdap3) inSKILL.mdandreferences/integration-guide.md. - Boundary markers: Generally absent in the provided code templates.
- Capability inventory: Network requests via
httpx, LDAP operations vialdap3, and local shell execution via thekanidmCLI tools. - Sanitization: The skill explicitly recommends and provides examples of escaping LDAP filter characters to prevent injection attacks.
Audit Metadata