databricks-lakebase
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies extensively on the
databricks postgresCLI command group and thepsqlutility to manage database resources, generate credentials, and execute SQL. These operations are the primary functions of the skill and target the user's Databricks environment. - [EXTERNAL_DOWNLOADS]: The skill references the installation of the
@databricks/lakebaseNode.js package and thedatabricks-sdkPython package. These are official vendor resources provided by Databricks for application integration and automation. - [DYNAMIC_EXECUTION]: The skill contains utility scripts that use
python3 -cto parse JSON output from CLI commands into environment variables andnpx tsxto execute local database migration scripts. These are standard developer practices for shell scripting and local development workflows. - [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection as it facilitates the synchronization of data between external Postgres databases and internal Unity Catalog Delta tables.
- Ingestion points: Data enters the environment via Lakebase synced tables (Unity Catalog to Postgres) and Lakehouse Sync (Postgres to Unity Catalog).
- Boundary markers: The instructions do not specify content-level delimiters for the data being synced, as it is treated as structured database content.
- Capability inventory: The skill utilizes
databricks postgres create-synced-tableandcreate-cdf-configto manage automated data pipelines. - Sanitization: The documentation recommends sanitizing null bytes (0x00) from source strings to prevent pipeline failures, though this is a data integrity measure rather than a prompt injection defense.
Audit Metadata