broadway-data-pipelines
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a data ingestion pipeline which processes external message payloads, creating a surface for indirect prompt injection.
- Ingestion points:
handle_message/3callback inSKILL.mdandassets/broadway_pipeline_template.exreceives data from external producers such as SQS or Kafka. - Boundary markers: The skill instructions (Rule 5) explicitly mandate treating all payloads as untrusted and rejecting malformed or oversized input.
- Capability inventory: Database insertion via
MyApp.Repo.insert_alland external queue operations viaDeadLetterQueue.sendandRequeue.push. - Sanitization: The provided template includes JSON decoding (
Jason.decode), input validation logic (validate/1), and data truncation (String.slice) to mitigate injection risks.
Audit Metadata