data-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection to execute shell commands during the initialization phase.
  • Evidence: !cat skills/_shared/protocols/ux-protocol.md 2>/dev/null || true in SKILL.md.
  • Evidence: !cat .production-grade.yaml 2>/dev/null || echo "No config — using defaults" in SKILL.md.
  • The commands are used to load project-specific configuration and shared protocol files. While this executes shell commands at load time, the activity is confined to reading local files within the skill's environment and does not involve exfiltration or unauthorized system access.
  • [PROMPT_INJECTION]: The skill is designed to process data from untrusted external sources, creating a surface for indirect prompt injection.
  • Ingestion points: Data is ingested from various external sources including APIs, databases, files, and streams as specified in the 'Data Architecture' and 'Ingestion Pipelines' phases.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard potential instructions embedded within the ingested data.
  • Capability inventory: The skill has the capability to execute shell commands (via dynamic context injection) and generate code for complex data pipelines that perform network and file operations.
  • Sanitization: While the skill emphasizes data quality tests (null checks, uniqueness, schema validation), these are focused on data integrity rather than security sanitization against malicious prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 07:55 AM
Security Audit — agent-trust-hub — data-engineer