malloy-scope
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing data from external databases via
execute_queryandget_context, which represents a theoretical surface for indirect prompt injection. - Ingestion points: The skill ingests untrusted data distributions and schema metadata through
execute_queryandget_contextcalls described in SKILL.md. - Boundary markers: Absent. The instructions do not define specific delimiters or instructions to ignore embedded commands within the database data.
- Capability inventory: The skill utilizes
execute_queryfor database interaction and writes results tomodeling-notes.md. - Sanitization: Absent. There is no explicit requirement for the agent to sanitize or escape data retrieved from the database before presenting it or recording it in notes.
- [COMMAND_EXECUTION]: The skill uses the
execute_querytool to perform row counts and data quality checks. This behavior is consistent with the skill's primary stated purpose of facilitating data modeling and analytical scope discovery.
Audit Metadata