devops-dataops

Warn

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Documentation provides numerous shell scripts and GitHub Action workflow templates that execute potentially destructive or sensitive commands like 'dbt build', 'sqlfluff fix', and 'aws s3 sync'.
  • [EXTERNAL_DOWNLOADS]: Configures CI/CD environments to fetch software from public registries and third-party repositories, including 'dbt-core', 'sqlfluff', 'great-expectations', and several community-maintained GitHub Actions.
  • [PROMPT_INJECTION]: The skill protocol explicitly instructs the agent to bypass standard communication guardrails by forbidding preambles, postambles, and explanations, which reduces user oversight of agent actions.
  • [DATA_EXFILTRATION]: Provides templates and instructions for transferring local build artifacts and generated documentation to external S3 buckets, establishing a mechanism that could be misused for unauthorized data movement.
  • [PROMPT_INJECTION]: Employs deceptive metadata and an extreme volume of repetitive 'haystack' content across reference files to obscure intent and hinder thorough manual security auditing.
  • [COMMAND_EXECUTION]: Includes Python code snippets that construct database queries using f-string interpolation ('pd.read_sql'), which creates a significant SQL injection risk if schema or table names are derived from untrusted inputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 02:15 PM
Security Audit — agent-trust-hub — devops-dataops