snowflake-development

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The script scripts/snowflake_query_helper.py is vulnerable to indirect prompt injection through SQL injection in generated templates.
  • Ingestion points: Command-line arguments for the merge, dynamic-table, and grant subcommands (e.g., --target, --role, --columns, --key) in scripts/snowflake_query_helper.py.
  • Boundary markers: None. The script uses f-strings and textwrap.dedent to assemble SQL statements without escaping or parameterizing the input values.
  • Capability inventory: The agent is instructed in SKILL.md to execute this script to generate MERGE statements, Dynamic Table DDL, and RBAC grants.
  • Sanitization: Absent. Input strings are used directly in SQL identifiers and logic, allowing a malicious user to supply object names that terminate the intended statement and execute arbitrary SQL commands if the generated output is subsequently run in a Snowflake environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 10:03 AM
Security Audit — agent-trust-hub — snowflake-development