databricks-python-sdk

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading data from external sources such as Databricks SQL tables, Unity Catalog Volumes, and Model Serving endpoints. This creates a surface for indirect prompt injection if the data being processed contains malicious instructions designed to manipulate the agent's logic.
  • Ingestion points: External data enters the agent context through methods such as w.statement_execution.execute_statement (file: examples/3-sql-and-warehouses.py), w.files.download (file: examples/4-unity-catalog.py), and w.serving_endpoints.query (file: examples/5-serving-and-vector-search.py).
  • Boundary markers: Documentation examples do not explicitly show the use of delimiters or warnings to ignore instructions within the retrieved data content.
  • Capability inventory: The skill provides capabilities to write files to the workspace (w.files.upload), create and run jobs (w.jobs.create), and manage compute resources (w.clusters.create).
  • Sanitization: The skill follows security best practices by demonstrating the use of StatementParameterListItem for SQL parameterization in examples/3-sql-and-warehouses.py, which mitigates SQL injection risks at the database level.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 02:31 AM