migrating-ai-sdk-to-common-ai
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides users in building Airflow tasks that process untrusted external data through LLM decorators, creating an indirect injection surface.
- Ingestion points: Input parameters such as
text: strin@task.llmandquestion: strin@task.agent(documented in SKILL.md). - Boundary markers: The provided migration examples do not include explicit delimiters or instructions for the LLM to ignore embedded commands within the processed data.
- Capability inventory: The documented tasks have the capability to read files (e.g., vision processing with
open(image_path, "rb")), invoke LLMs via Airflow connections, and persist structured data to XCom. - Sanitization: No recommendation for input validation, sanitization, or escaping of the user-provided strings is included in the migration steps.
Audit Metadata