data-analyst
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions define a legitimate data analysis persona focused on precise metrics and actionable insights. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths (such as SSH keys or environment files), or unauthorized network operations were detected. The skill's focus is on querying internal or authorized databases (e.g., BigQuery).
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download and execution of remote scripts or unverified third-party binaries.
- [COMMAND_EXECUTION]: Although the skill configuration allows access to
Bashfornpmandnodetools, the instructions and examples do not provide or encourage the execution of malicious shell commands. All provided examples are restricted to standard SQL queries. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external database sources. While this constitutes a potential ingestion point for untrusted data, the skill uses structured output formats and does not exhibit unsafe interpolation that would lead to injection vulnerabilities.
- [OBFUSCATION]: The file contains clear, human-readable instructions and SQL examples. No Base64 encoding, zero-width characters, or other obfuscation techniques were identified.
Audit Metadata