data-data-catalog

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits extreme context stuffing across multiple reference files including architecture-patterns.md, code-organization.md, deployment-pipelines.md, error-handling.md, performance-optimization.md, security-best-practices.md, state-management.md, and testing-strategies.md. Each file contains 150 sections of repetitive, generic technical text regarding Zero Trust and kernel interactions. This massive redundancy obscures the skill's actual content and can lead to instruction confusion or performance degradation in the agent.
  • [PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection.
  • Ingestion points: Processes untrusted metadata from various sources such as Snowflake information_schema, dbt manifest.json, and Airflow DAGs as documented in references/catalog-metadata-automation.md.
  • Boundary markers: The provided code snippets and instructions do not implement delimiters or 'ignore' instructions for external content when processing metadata descriptions.
  • Capability inventory: Includes capabilities to perform network requests (requests, httpx), execute bash commands (Airflow bash tasks), and automate access provisioning (provision_access function in references/data-catalog-metadata-management.md).
  • Sanitization: Lacks sanitization or validation for descriptive fields which are interpolated into the catalog graph.
  • [EXTERNAL_DOWNLOADS]: The skill workflow relies on fetching metadata and lineage information from various external platforms including DataHub GMS, OpenMetadata server, Snowflake, BigQuery, and Tableau Metadata APIs.
  • [COMMAND_EXECUTION]: Includes instructions and code snippets for executing shell commands via Airflow tasks to perform metadata ingestion, specifically using the datahub CLI tool.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:22 PM
Security Audit — agent-trust-hub — data-data-catalog