rde-data-apps

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Bash script provided in Section 3 for writing credentials interpolates user-provided or environment-derived placeholders (<repo> and <url>) directly into shell commands (e.g., git -C "<repo>"). If these values are not strictly validated, it could lead to arbitrary command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external repositories and Metabase instance metadata, creating an attack surface where malicious instructions could be embedded in those sources.
  • Ingestion points: The skill reads repository files (e.g., databases/, collections/, queries/) and processes output from Metabase CLI tools (mb, rde).
  • Boundary markers: The skill implements manual confirmation checkpoints for synchronization steps (Section 6), providing a human-in-the-loop safety measure.
  • Capability inventory: The skill has access to Bash, Write, Edit, and Read tools, and executes commands like npm run build, git push/pull, and mb git-sync import.
  • Sanitization: There are no explicit instructions for sanitizing or escaping content read from the repository or CLI outputs before the agent acts upon them.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic context injection syntax (! rde init --only license) which triggers a shell command execution at the time the skill is loaded. This is used here for vendor-specific initialization and license activation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 11:16 PM