databricks-python-sdk
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading data from external sources such as Databricks SQL tables, Unity Catalog Volumes, and Model Serving endpoints. This creates a surface for indirect prompt injection if the data being processed contains malicious instructions designed to manipulate the agent's logic.
- Ingestion points: External data enters the agent context through methods such as
w.statement_execution.execute_statement(file:examples/3-sql-and-warehouses.py),w.files.download(file:examples/4-unity-catalog.py), andw.serving_endpoints.query(file:examples/5-serving-and-vector-search.py). - Boundary markers: Documentation examples do not explicitly show the use of delimiters or warnings to ignore instructions within the retrieved data content.
- Capability inventory: The skill provides capabilities to write files to the workspace (
w.files.upload), create and run jobs (w.jobs.create), and manage compute resources (w.clusters.create). - Sanitization: The skill follows security best practices by demonstrating the use of
StatementParameterListItemfor SQL parameterization inexamples/3-sql-and-warehouses.py, which mitigates SQL injection risks at the database level.
Audit Metadata