managed-airflow-migrations

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Command Execution]: The skill utilizes official Google Cloud CLI tools (gcloud, gcloud storage) and standard Unix utilities (grep) to manage Airflow environments and analyze DAG code. These operations are consistent with the skill's purpose of assisting in complex code migrations.
  • [Data Access and Migration]: The skill provides instructions for downloading and uploading DAG files between local storage and Google Cloud Storage (GCS) buckets. This behavior is necessary for the migration process and utilizes authenticated vendor tooling to ensure secure data handling.
  • [Indirect Prompt Injection Surface]: The skill analyzes user-provided DAG files to identify code patterns that require updates. This ingestion of untrusted data is a potential attack surface, but the skill mitigates risk by providing specific, targeted search commands (grep) for the agent to execute, rather than relying on open-ended analysis of the file content.
  • [Capability Inventory]: Analysis of the skill reveals capabilities for executing shell commands, interacting with cloud environments via gcloud, and performing file system operations in a local workspace. These capabilities are appropriately scoped to the migration task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:52 PM
Security Audit — agent-trust-hub — managed-airflow-migrations