projection-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern for ingesting untrusted event data (from an Event stream) and writing it directly into persistent storage (PostgreSQL via asyncpg and Elasticsearch). This creates an attack surface where malicious instructions embedded in event fields (like description, name, or cancellation_reason) could be stored and subsequently processed by an agent or LLM querying the read model.
  • Ingestion points: Event.data dictionary processed in SKILL.md (e.g., OrderSummaryProjection.apply, ProductSearchProjection.apply).
  • Boundary markers: None identified. Data is interpolated directly into SQL queries and Elasticsearch documents.
  • Capability inventory: File system access and network operations are not directly present in the templates, but the templates interact with external databases and search engines.
  • Sanitization: The skill uses parameterized queries ($1, $2) for SQL, which prevents SQL injection, but does not provide sanitization for the content of the strings before they are stored in the read model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — projection-patterns