cb-analytics-schema
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection risk. The
infer_schematool summarizes document contents from an external database. Malicious content within the database could potentially influence the agent's actions if it treats data as instructions. - Ingestion points: Data is pulled from datasets via
infer_schema(SKILL.md). - Boundary markers: There are no instructions provided to wrap the sampled data in delimiters or treat it as untrusted content.
- Capability inventory: The agent can execute queries via
execute_query_readonlyand list metadata (SKILL.md). - Sanitization: No sanitization is mentioned for the document contents being sampled.
- [COMMAND_EXECUTION]: Potential SQL injection surface. The skill instructions mention that dataset names are directly interpolated into SQL++ FROM clauses. While it notes that server-side validation is performed, this design pattern relies on external security controls rather than safe identifier handling.
Audit Metadata