data-pipeline-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance for building data pipelines using the Medallion architecture (Bronze/Silver/Gold) and modern data stack tools. The instructions are aligned with professional data engineering standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages pipelines that ingest untrusted data from external sources like Kafka and S3. It addresses this attack surface by implementing strong data contracts via Spark schemas and Great Expectations quality gates. The included validation script (scripts/validate-pipeline.sh) proactively scans for hardcoded configurations and missing watermarks that could affect pipeline stability.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool, but the YAML frontmatter correctly restricts execution to a specific whitelist of commands (dbt, spark-submit, airflow, and python). This implementation adheres to the principle of least privilege.
  • [EXTERNAL_DOWNLOADS]: External resources referenced in the documentation link to official, well-known services including the Apache Airflow, dbt Labs, Great Expectations, and Delta Lake documentation sites. These are documented neutrally as legitimate technical resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:36 AM
Security Audit — agent-trust-hub — data-pipeline-engineer