managing-superset
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill implements various administrative functions through bash scripts that execute system commands including curl, jq, and column to interact with the Superset API and format the output for the agent.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to an external Apache Superset instance using the URL and credentials provided in environment variables (SUPERSET_URL, SUPERSET_ACCESS_TOKEN, etc.).
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it retrieves and processes untrusted data from the Superset API, such as dashboard titles, chart names, and executed SQL query history, without explicit sanitization. This risk is inherent to the skill's purpose of managing an external data platform.
- Ingestion points: Data is ingested via the
superset_apihelper function throughout the SKILL.md file. - Boundary markers: The skill lacks explicit boundary markers in its scripts but provides a structured reporting template in the 'Output Format' section.
- Capability inventory: The skill utilizes subprocess execution (bash) and network operations (curl).
- Sanitization: No explicit sanitization or filtering of API response content is performed before presentation to the agent.
Audit Metadata