skills/redpanda-data/skills/connect/Gen Agent Trust Hub

connect

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides technical documentation for Redpanda Connect (formerly Benthos), a declarative stream processor. All code snippets are functional examples for configuring data inputs, processors, and outputs.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No sensitive data exposure was detected. The skill correctly advocates for using environment variable interpolation (e.g., ${REDPANDA_PASSWORD}) and dedicated secrets management URNs (e.g., aws://, gcp://) to handle credentials securely.
  • [COMMAND_EXECUTION]: The skill describes the use of standard rpk connect and redpanda-connect CLI tools for running, linting, and dry-running pipelines. These are legitimate administrative operations for the documented tool.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill mentions downloading the binary and using Docker, which are standard deployment methods for the product.
  • [INDIRECT_PROMPT_INJECTION]: While the pipelines described ingest data from external sources (HTTP, Kafka, S3, etc.), the skill's purpose is to teach the configuration of these pipelines. It does not instruct the agent to interpret processed data as instructions, which limits the risk of indirect injection during the agent's interaction with the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:50 PM
Security Audit — agent-trust-hub — connect