query-aepipe
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions in
SKILL.mdprovide clear operational guidance for the agent. No attempts to bypass safety filters or override system instructions were identified.\n- [DATA_EXFILTRATION]: Network activity is confined to the user-defined API endpoint. The skill does not attempt to access sensitive system files like SSH keys or AWS credentials for transmission to unauthorized locations.\n- [COMMAND_EXECUTION]: The skill uses local Python scripts for its core logic. A best-practice violation was noted inquery_processor.pywhere SQL schema is dynamically generated from input data keys; however, this is restricted to the local SQLite export feature and does not allow for arbitrary system command execution.\n- [CREDENTIALS_UNSAFE]: Thesetup_config.pyscript securely handles the administrative API token by storing it in a local JSON file with restricted filesystem permissions (0o600).\n- [EXTERNAL_DOWNLOADS]: No external code or package downloads are performed at runtime. The skill relies exclusively on the Python standard library.
Audit Metadata