databricks-lakebase

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies extensively on the databricks postgres CLI command group and the psql utility to manage database resources, generate credentials, and execute SQL. These operations are the primary functions of the skill and target the user's Databricks environment.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the @databricks/lakebase Node.js package and the databricks-sdk Python package. These are official vendor resources provided by Databricks for application integration and automation.
  • [DYNAMIC_EXECUTION]: The skill contains utility scripts that use python3 -c to parse JSON output from CLI commands into environment variables and npx tsx to execute local database migration scripts. These are standard developer practices for shell scripting and local development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection as it facilitates the synchronization of data between external Postgres databases and internal Unity Catalog Delta tables.
  • Ingestion points: Data enters the environment via Lakebase synced tables (Unity Catalog to Postgres) and Lakehouse Sync (Postgres to Unity Catalog).
  • Boundary markers: The instructions do not specify content-level delimiters for the data being synced, as it is treated as structured database content.
  • Capability inventory: The skill utilizes databricks postgres create-synced-table and create-cdf-config to manage automated data pipelines.
  • Sanitization: The documentation recommends sanitizing null bytes (0x00) from source strings to prevent pipeline failures, though this is a data integrity measure rather than a prompt injection defense.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:30 AM