dotnet-messaging-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard architectural patterns and code snippets for .NET messaging without introducing security risks.\n- [SAFE]: The code snippets use placeholders for sensitive connection strings, and the 'Agent Gotchas' section explicitly advises against hardcoding credentials in favor of environment variables or secret managers. The use of 'guest/guest' in the MassTransit snippet refers to well-known default credentials for local RabbitMQ development.\n- [SAFE]: The dependencies listed (e.g., MassTransit, Azure.Messaging.ServiceBus) are widely used, reputable .NET libraries.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes processing external data (messages from a broker) using JSON deserialization.\n
- Ingestion points: Data enters the system via
args.Message.Bodyin Azure Service Bus orConsumeContext<T>in MassTransit consumers inSKILL.md.\n - Boundary markers: None explicitly defined in the snippets.\n
- Capability inventory: Examples include database writes (
db.SaveChangesAsync()) and network messaging (publishEndpoint.Publish()) inSKILL.md.\n - Sanitization: The patterns utilize strongly-typed deserialization (
ToObjectFromJson<T>), which mitigates injection risks by enforcing expected data structures.
Audit Metadata