malloy-lookml-review
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to read and process external LookML (.lkml) files to extract business logic, dimensions, and relationships. These files act as untrusted data sources that could contain malicious instructions.
- Ingestion points: The agent scans and reads .lkml files, including views, explores, and manifests, as detailed in
reference/discover.mdandreference/propose-fields.md. - Boundary markers: The instructions do not explicitly mandate the use of delimiters or specific warnings to ignore instructions embedded within the processed LookML content, although it notes to strip Liquid templates.
- Capability inventory: The skill utilizes the
execute_querytool to run SQL against a database and filesystem tools to read project files. This allows an attacker who controls the input files to potentially execute arbitrary SQL or influence agent behavior if the agent is tricked into following instructions inside the files. - Sanitization: While the skill suggests simplifying complex SQL and stripping Liquid code, it lacks a robust sanitization process for SQL expressions extracted from LookML before they are passed to execution tools.
Audit Metadata