airflow-plugins
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and code skeletons for extending Airflow 3.1+ functionality. No malicious patterns, obfuscation, or unauthorized access attempts were detected.
- [CREDENTIALS_UNSAFE]: The code snippets include default development credentials ('admin'/'admin') for local environments. However, the documentation correctly instructs users to use environment variables for production secrets and provides specific guidance for managing Astronomer Astro Deployment API tokens.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and repositories from trusted organizations, including the Apache Software Foundation and Astronomer. These references are used for standard dependency management and developer education.
- [INDIRECT_PROMPT_INJECTION]: The skill includes a 'Streaming proxy' example that processes a filename path parameter. While this creates a theoretical surface for path manipulation if not sanitized by the implementing developer, it is presented as a standard code template for proxying external assets and does not represent a malicious design in the skill itself.
Audit Metadata