malloy-analysis-report

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing formatting and design patterns for creating .malloynb notebook files.
  • [COMMAND_EXECUTION]: The skill mentions platform tools such as execute_query and search_malloy_docs. These are intended for data analysis within the Malloy ecosystem and do not represent unauthorized command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow for processing and presenting data that may originate from untrusted sources.
  • Ingestion points: Malloy queries and markdown text are ingested into the notebook structure (described in SKILL.md).
  • Boundary markers: The skill explicitly requires the use of >>>markdown and >>>malloy delimiters to separate code from narrative.
  • Capability inventory: Uses the execute_query tool (mentioned in SKILL.md).
  • Sanitization: The instructions mandate a 'verify-then-assemble' workflow, requiring the agent to run queries via execute_query and explain results to the user before final report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:02 AM
Security Audit — agent-trust-hub — malloy-analysis-report