projection-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern for ingesting untrusted event data (from an
Eventstream) and writing it directly into persistent storage (PostgreSQL viaasyncpgand Elasticsearch). This creates an attack surface where malicious instructions embedded in event fields (likedescription,name, orcancellation_reason) could be stored and subsequently processed by an agent or LLM querying the read model. - Ingestion points:
Event.datadictionary processed inSKILL.md(e.g.,OrderSummaryProjection.apply,ProductSearchProjection.apply). - Boundary markers: None identified. Data is interpolated directly into SQL queries and Elasticsearch documents.
- Capability inventory: File system access and network operations are not directly present in the templates, but the templates interact with external databases and search engines.
- Sanitization: The skill uses parameterized queries (
$1,$2) for SQL, which prevents SQL injection, but does not provide sanitization for the content of the strings before they are stored in the read model.
Audit Metadata