bigquery-ai-ml
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Potential for Indirect Prompt Injection: Several functions described in the skill, such as
AI.GENERATE,AI.AGG, andAI.IF, combine natural language instructions with data sourced from tables, which could potentially lead to instruction override if the data is untrusted. - Ingestion points: Untrusted data enters the model context via BigQuery table columns, as seen in
references/ai_generate.md(e.g.,article_content) andreferences/ai_agg.md(e.g.,review). - Boundary markers: The provided examples typically use simple string concatenation (e.g.,
'Summarize this article: ' || article_content) or structs without explicit delimiters or instructions to the model to ignore embedded commands within the data. - Capability inventory: These functions have the capability to invoke Vertex AI models (such as Gemini) to perform text generation, classification, and scoring directly within SQL queries.
- Sanitization: The examples do not demonstrate sanitization or validation of the input data before it is passed to the AI functions, which is a common pattern in documentation focused on functionality rather than security hardening.
- Use of Vendor-Owned External Resources: The skill references datasets and storage locations hosted by the vendor to provide realistic examples.
- Evidence: References to Google Cloud Storage (e.g.,
gs://cloud-samples-data/) and public BigQuery datasets (e.g.,bigquery-public-data) are used to illustrate how to process images and public text data.
Audit Metadata