malloy-scope

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing data from external databases via execute_query and get_context, which represents a theoretical surface for indirect prompt injection.
  • Ingestion points: The skill ingests untrusted data distributions and schema metadata through execute_query and get_context calls described in SKILL.md.
  • Boundary markers: Absent. The instructions do not define specific delimiters or instructions to ignore embedded commands within the database data.
  • Capability inventory: The skill utilizes execute_query for database interaction and writes results to modeling-notes.md.
  • Sanitization: Absent. There is no explicit requirement for the agent to sanitize or escape data retrieved from the database before presenting it or recording it in notes.
  • [COMMAND_EXECUTION]: The skill uses the execute_query tool to perform row counts and data quality checks. This behavior is consistent with the skill's primary stated purpose of facilitating data modeling and analytical scope discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 12:42 PM
Security Audit — agent-trust-hub — malloy-scope