cds-modeling
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, such as business requirements and existing CDS schema files, which serves as a potential attack surface for indirect instructions.
- Ingestion points: The agent processes user-provided business descriptions and reviews local
schema.cdsfiles as part of its core workflow defined inagents/cds-modeler.md. - Boundary markers: The instructions do not define specific delimiters or strict guidance to help the agent distinguish between data and potentially malicious commands embedded within the processed content.
- Capability inventory: The skill's primary function is generating and reviewing CDS code; it does not request or utilize tools for network access, file system modifications, or command execution.
- Sanitization: There are no explicit instructions for the agent to sanitize, filter, or validate the content of the ingested files before processing them.
Audit Metadata