using-data-dev

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a declarative router, mapping user utterances to specific internal data development skills (such as finance-ddl-design and finance-pipeline-dev). It does not process data or execute code directly.\n- [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was detected. The skill instructions explicitly prohibit connecting to data sources, performing queries, or generating business deliverables.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied natural language to determine routing paths. While this is a data ingestion surface, the risk is negligible because the skill lacks executable capabilities and only transitions control to other internal components.\n
  • Ingestion points: Natural language user requests regarding data engineering tasks in SKILL.md.\n
  • Boundary markers: None explicitly defined.\n
  • Capability inventory: None (orchestration and routing only).\n
  • Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 01:29 AM
Security Audit — agent-trust-hub — using-data-dev