rde-data-apps
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The Bash script provided in Section 3 for writing credentials interpolates user-provided or environment-derived placeholders (
<repo>and<url>) directly into shell commands (e.g.,git -C "<repo>"). If these values are not strictly validated, it could lead to arbitrary command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external repositories and Metabase instance metadata, creating an attack surface where malicious instructions could be embedded in those sources.
- Ingestion points: The skill reads repository files (e.g.,
databases/,collections/,queries/) and processes output from Metabase CLI tools (mb,rde). - Boundary markers: The skill implements manual confirmation checkpoints for synchronization steps (Section 6), providing a human-in-the-loop safety measure.
- Capability inventory: The skill has access to
Bash,Write,Edit, andReadtools, and executes commands likenpm run build,git push/pull, andmb git-sync import. - Sanitization: There are no explicit instructions for sanitizing or escaping content read from the repository or CLI outputs before the agent acts upon them.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic context injection syntax (
! rde init --only license) which triggers a shell command execution at the time the skill is loaded. This is used here for vendor-specific initialization and license activation.
Audit Metadata