business-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation, architectural guidance, and best practices for implementing semantic layers (like dbt MetricFlow or Cube). It does not contain executable code beyond a local utility script.
  • [COMMAND_EXECUTION]: The included scripts/verify.sh script is a read-only bash utility designed to lint semantic model files. It uses standard Linux utilities (grep, find, sed) and optionally python3 or yq for syntax validation. The script is explicitly designed to be offline and never connects to external data warehouses.
  • [DATA_EXFILTRATION]: Analysis of the instructions and scripts shows no evidence of network operations, credential harvesting, or unauthorized data access. All operations are confined to the local filesystem and the agent's interaction with governed APIs.
  • [PROMPT_INJECTION]: The skill instructions emphasize grounding the agent in a structured semantic layer, which actually serves as a security control to prevent the agent from generating arbitrary or malicious SQL queries directly against raw database tables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — business-intelligence