elasticsearch-esql

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows best practices by instructing the agent to use the official elastic CLI for all operations, avoiding direct HTTP API calls or credential guessing. All instructions are focused on providing accurate query generation based on the user's intent.
  • [SAFE]: All references to external documentation and software target the official Elastic organization and infrastructure. The skill does not download or execute code from untrusted remote sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes results from external Elasticsearch queries. While this presents a theoretical surface for indirect prompt injection if the queried data is malicious, the instructions emphasize using clean tabular (TSV) output to mitigate parsing risks and provide clear boundaries for data handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:34 AM
Security Audit — agent-trust-hub — elasticsearch-esql