malloy-analysis-report
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing formatting and design patterns for creating
.malloynbnotebook files. - [COMMAND_EXECUTION]: The skill mentions platform tools such as
execute_queryandsearch_malloy_docs. These are intended for data analysis within the Malloy ecosystem and do not represent unauthorized command execution. - [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow for processing and presenting data that may originate from untrusted sources.
- Ingestion points: Malloy queries and markdown text are ingested into the notebook structure (described in
SKILL.md). - Boundary markers: The skill explicitly requires the use of
>>>markdownand>>>malloydelimiters to separate code from narrative. - Capability inventory: Uses the
execute_querytool (mentioned inSKILL.md). - Sanitization: The instructions mandate a 'verify-then-assemble' workflow, requiring the agent to run queries via
execute_queryand explain results to the user before final report generation.
Audit Metadata