data-analyst

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The sub-agent processes external, potentially untrusted data from BigQuery and Snowflake tables, which presents an indirect prompt injection surface.
  • Ingestion points: Data results fetched from external databases via google-cloud-bigquery and snowflake connections.
  • Boundary markers: Absent. The skill instructions do not specify the use of delimiters or specific instructions to treat the ingested data as non-executable text.
  • Capability inventory: The agent has the capability to execute shell commands (gcloud, marimo, python) and write to the local filesystem (data/output/, reports/, notebooks/).
  • Sanitization: Absent. There are no instructions for validating or escaping the content of data retrieved from the database before it is used in the context of analysis or file generation.
  • [COMMAND_EXECUTION]: The skill relies on executing system-level commands to manage authentication and perform its primary tasks.
  • Evidence: Instructs the agent to use gcloud config configurations activate and gcloud auth application-default login for GCP environment setup.
  • Evidence: Executes marimo edit for notebook management and a local script python scripts/lint_marimo_vars.py for code quality checks. Note that the content of the linting script is not included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:58 AM
Security Audit — agent-trust-hub — data-analyst