malloy-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes proactive defensive measures against indirect prompt injection. It explicitly instructs the agent to treat external metadata (like #(doc) strings) and query results as data to be analyzed rather than instructions to be followed. This mitigates risks associated with malicious content embedded in database schemas or records.
  • [COMMAND_EXECUTION]: The skill involves the dynamic construction and execution of Malloy queries via the execute_query tool. This is the primary intended function of the skill and is implemented following best practices, including entity discovery and verification steps to ensure query integrity.
  • [DATA_EXFILTRATION]: Data access is scoped to the Malloy semantic models provided via the host's MCP (Model Context Protocol). The skill contains no hardcoded credentials or instructions to send data to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:02 AM
Security Audit — agent-trust-hub — malloy-analysis