databricks-uc-migration-pilot

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the databricks, jq, aws, and python3 binaries. These operations are used for legitimate platform interactions, such as fetching table metadata, enabling system schemas, and performing read-only IAM introspection for storage diagnosis.
  • [PROMPT_INJECTION]: The presence of prompt injection strings in eval-spec.yaml is a false positive related to security testing. The strings are part of a test case (id: prompt-injection) designed to ensure the model resists adversarial instructions.
  • [DYNAMIC_EXECUTION]: The bundled Python scripts (audit-hms-readiness.py and enable-system-schemas.py) dynamically generate SQL statements for the Databricks Statement Execution API. This is a core functional requirement for auditing the Hive Metastore and applying Unity Catalog grants.
  • [DATA_EXPOSURE]: The skill accesses metadata related to data governance and storage paths. These actions are performed using the user's existing environment credentials and results are stored in local output files for human review, adhering to best practices for migration planning.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — databricks-uc-migration-pilot