data-pipelines
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform a local filesystem check using the ls command to identify installed companion skills in paths like ~/.claude/skills/ and ~/.agent/skills/ upon initial activation.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and process data pipeline configurations and SQL code without specifying sanitization methods or clear boundary delimiters for untrusted inputs. Evidence: 1. Ingestion points: User-provided pipeline designs, SQL queries, and Airflow DAG scripts (SKILL.md, references/). 2. Boundary markers: None identified. 3. Capability inventory: Shell command execution via the agent's environment (e.g., ls, npx). 4. Sanitization: No input filtering or escaping is specified in the instructions.
Audit Metadata