data-data-platform

Warn

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill's reference documentation (e.g., architecture-patterns.md, code-organization.md, deployment-pipelines.md, etc.) contains an extreme volume of repetitive filler text. Each file contains 150 sections that cycle through the same 5-10 technical paragraphs thousands of times. This technique creates a massive context window that obscures content and can hinder effective security auditing by hiding instructions within a wall of noise.
  • [PROMPT_INJECTION]: Deceptive documentation practices. The reference files are labeled as "Ultimate Deep Dives" intended for "Staff+ Engineers," but the content is low-value, repetitive technical boilerplate. This misleading framing can cause users to misjudge the maturity and safety of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill's examples reference external container images (ghcr.io/org/spark-iceberg, myrepo/spark-py) and Git repositories (github.com/org/data-pipelines.git). Although these are placeholders (using 'org'), they represent points where external code is introduced into the environment and must be verified before deployment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 27, 2026, 07:49 AM
Security Audit — agent-trust-hub — data-data-platform