senior-data-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/pipeline_orchestrator.pyemploys thecompile()function within the validation methods of itsAirflowGenerator,PrefectGenerator, andDagsterGeneratorclasses. This call is used to perform syntax checks on the Python code generated by the tool to ensure its validity before it is saved to a file or presented to the user. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function of generating code based on user-supplied parameters (e.g., table names, schedule expressions, and data schemas) creates an inherent surface for indirect prompt injection.
- Ingestion points: User-provided CLI arguments and configuration files (YAML/JSON) ingested by
pipeline_orchestrator.py,data_quality_validator.py, andetl_performance_optimizer.py. - Boundary markers: Not explicitly defined in the template interpolation logic within the generation scripts.
- Capability inventory: The skill provides functionality to write generated Python scripts to the filesystem and performs syntax validation using
compile(). - Sanitization: The code generation logic uses standard string formatting to populate templates with user input, without specialized sanitization for potential code injection in the generated output.
Audit Metadata