Back to plugin

Security audit

Identity AIops

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a disclosed identity-operations tool for Keycloak and authentik, but users should grant it only the identity-provider permissions they actually want an agent to use.

Install only for environments where you want an agent to inspect and potentially operate Keycloak or authentik. Start with view-only IdP roles, add manage permissions only when needed, and remember that MCP write tools can change accounts, sessions, clients, and secrets if the configured credential allows it.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/identity-aiops/references/cli-reference.md:28
Evidence
Master password: `[REDACTED]` (non-interactive/MCP) or an

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/identity-aiops/references/agent-guardrails.md:88
Evidence
Copy this into your agent's system prompt: