cb-analytics-schema

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection risk. The infer_schema tool summarizes document contents from an external database. Malicious content within the database could potentially influence the agent's actions if it treats data as instructions.
  • Ingestion points: Data is pulled from datasets via infer_schema (SKILL.md).
  • Boundary markers: There are no instructions provided to wrap the sampled data in delimiters or treat it as untrusted content.
  • Capability inventory: The agent can execute queries via execute_query_readonly and list metadata (SKILL.md).
  • Sanitization: No sanitization is mentioned for the document contents being sampled.
  • [COMMAND_EXECUTION]: Potential SQL injection surface. The skill instructions mention that dataset names are directly interpolated into SQL++ FROM clauses. While it notes that server-side validation is performed, this design pattern relies on external security controls rather than safe identifier handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:52 AM
Security Audit — agent-trust-hub — cb-analytics-schema