broadway-data-pipelines

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a data ingestion pipeline which processes external message payloads, creating a surface for indirect prompt injection.
  • Ingestion points: handle_message/3 callback in SKILL.md and assets/broadway_pipeline_template.ex receives data from external producers such as SQS or Kafka.
  • Boundary markers: The skill instructions (Rule 5) explicitly mandate treating all payloads as untrusted and rejecting malformed or oversized input.
  • Capability inventory: Database insertion via MyApp.Repo.insert_all and external queue operations via DeadLetterQueue.send and Requeue.push.
  • Sanitization: The provided template includes JSON decoding (Jason.decode), input validation logic (validate/1), and data truncation (String.slice) to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:12 PM
Security Audit — agent-trust-hub — broadway-data-pipelines