airflow-plugins

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code skeletons for extending Airflow 3.1+ functionality. No malicious patterns, obfuscation, or unauthorized access attempts were detected.
  • [CREDENTIALS_UNSAFE]: The code snippets include default development credentials ('admin'/'admin') for local environments. However, the documentation correctly instructs users to use environment variables for production secrets and provides specific guidance for managing Astronomer Astro Deployment API tokens.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and repositories from trusted organizations, including the Apache Software Foundation and Astronomer. These references are used for standard dependency management and developer education.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a 'Streaming proxy' example that processes a filename path parameter. While this creates a theoretical surface for path manipulation if not sanitized by the implementing developer, it is presented as a standard code template for proxying external assets and does not represent a malicious design in the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:35 PM
Security Audit — agent-trust-hub — airflow-plugins