omni-query
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
omniCLI, a vendor-specific tool for Omni Analytics. It provides numerous examples of shell commands for configuration (omni config), authentication (omni whoami), and data operations (omni query run,omni ai job-submit). - [DYNAMIC_EXECUTION]: The skill explicitly supports running raw SQL queries via the
userEditedSQLparameter. The documentation provides a security warning that this pathway bypasses topic-level access controls and row-level security, recommending topic-based queries where possible. This represents a functional requirement of the tool rather than a malicious back door. - [INDIRECT_PROMPT_INJECTION]: By integrating AI-powered query generation (
omni aicommands), the skill creates a surface for indirect prompt injection. A user could provide natural language that results in the generation of queries designed to exfiltrate data or bypass semantic constraints. The skill provides extensive validation guidance, including checking row counts and comparing filtered vs. unfiltered results, to mitigate these risks. - [EXTERNAL_DOWNLOADS]: The skill provides links to the official Omni CLI GitHub repository for installation and documentation purposes. These references target a trusted vendor domain (
exploreomni) and are documented neutrally for the user's benefit.
Audit Metadata