omni-to-snowflake-semantic-view

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes legitimate CLI tools to manage configurations and query data from external platforms.\n
  • Evidence: Uses the Omni CLI (omni) and Snowflake tools (snow, snowsql) for model exploration and SQL execution.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing a standard integration library for Snowflake connectivity.\n
  • Evidence: Recommends the installation of snowflake-connector-python via pip.\n- [DYNAMIC_EXECUTION]: The skill generates SQL statements by mapping and concatenating metadata from external YAML definitions into database-ready expressions.\n
  • Execution method: SQL execution through terminal-based CLIs or Python scripts.\n
  • Patterns: Translates Omni dimension and measure logic into SQL CASE WHEN and COALESCE expressions for Snowflake Semantic Views.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external metadata files that serve as the foundation for code generation, presenting a potential injection surface.\n
  • Ingestion points: Data extracted from Omni topic, view, and relationship YAML files via omni models yaml-get (SKILL.md).\n
  • Boundary markers: None specified to delimit or sanitize the imported field definitions.\n
  • Capability inventory: Shell command execution and SQL query processing.\n
  • Sanitization: No explicit validation of field names or SQL expressions provided in the source YAML is detailed in the conversion logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:05 PM
Security Audit — agent-trust-hub — omni-to-snowflake-semantic-view