elasticsearch-esql
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill follows best practices by instructing the agent to use the official
elasticCLI for all operations, avoiding direct HTTP API calls or credential guessing. All instructions are focused on providing accurate query generation based on the user's intent. - [SAFE]: All references to external documentation and software target the official Elastic organization and infrastructure. The skill does not download or execute code from untrusted remote sources.
- [INDIRECT_PROMPT_INJECTION]: The skill processes results from external Elasticsearch queries. While this presents a theoretical surface for indirect prompt injection if the queried data is malicious, the instructions emphasize using clean tabular (TSV) output to mitigate parsing risks and provide clear boundaries for data handling.
Audit Metadata