cds-modeling

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, such as business requirements and existing CDS schema files, which serves as a potential attack surface for indirect instructions.
  • Ingestion points: The agent processes user-provided business descriptions and reviews local schema.cds files as part of its core workflow defined in agents/cds-modeler.md.
  • Boundary markers: The instructions do not define specific delimiters or strict guidance to help the agent distinguish between data and potentially malicious commands embedded within the processed content.
  • Capability inventory: The skill's primary function is generating and reviewing CDS code; it does not request or utilize tools for network access, file system modifications, or command execution.
  • Sanitization: There are no explicit instructions for the agent to sanitize, filter, or validate the content of the ingested files before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 09:17 AM
Security Audit — agent-trust-hub — cds-modeling