malloy-discover
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by instructing the agent to ingest and act upon various untrusted external files, such as metadata.json and project documentation, which could contain malicious instructions influencing subsequent database queries.
- Ingestion points: The agent is directed to read external files including metadata.json, dbt_project.yml, KPI documentation, and README files to identify 'prior art signals' (identified in the Workflow and Prior Art Detection sections).
- Boundary markers: None identified. The skill lacks instructions to the agent to treat external content as untrusted or to implement boundary markers between external data and system instructions.
- Capability inventory: The agent has the capability to execute arbitrary Malloy and SQL queries via the execute_query tool, using information derived from the untrusted external files to validate assumptions and preview data (identified in the Tools and Workflow sections).
- Sanitization: No evidence of sanitization or content filtering was found; the instructions encourage the agent to read external files directly without verification of the content source or integrity.
Audit Metadata