projection-patterns
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by providing templates that process and store external event data. \n- Ingestion points: The event.data object is used throughout the implementation templates in resources/implementation-playbook.md to populate read models. \n- Boundary markers: No specific delimiters or instructions are provided to the agent to treat event.data content as untrusted or to ignore potentially embedded instructions within the event stream. \n- Capability inventory: The skill utilizes asyncpg for PostgreSQL database writes and the elasticsearch library for search index updates across multiple templates. \n- Sanitization: Code samples demonstrate the use of parameterized queries (e.g., $1, $2), which provides a defense mechanism against conventional injection techniques while handling external data inputs.
Audit Metadata