data-data-virtualization
Warn
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits extreme 'token bloat' or metadata poisoning across several reference files (e.g.,
references/architecture-patterns.md,references/code-organization.md,references/deployment-pipelines.md,references/error-handling.md,references/performance-optimization.md,references/security-best-practices.md,references/state-management.md, andreferences/testing-strategies.md). These files contain up to 150 sections of repetitive, generic technical fluff. This volume of redundant data can be used to exhaust the agent's context window, potentially displacing critical system prompts or security guidelines. - [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8).
- Ingestion points: Data is ingested from multiple external federated sources including PostgreSQL, Hive, Iceberg, MongoDB, and Elasticsearch as described in
SKILL.md(Step 3) andreferences/virtualization-connectors.md. - Boundary markers: There are no boundary markers or explicit instructions provided to the agent to treat data retrieved from these sources as untrusted or to ignore embedded instructions.
- Capability inventory: The agent has the capability to coordinate and execute complex cross-source joins and query source systems directly (
SKILL.mdStep 5). - Sanitization: There is no evidence of input validation, sanitization, or escaping of the data retrieved from external sources before it is processed by the agent.
Audit Metadata