data-pipeline-spec

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and provides a framework for the AI to generate a Data Pipeline Specification document. It does not contain any executable scripts, command line operations, or network requests.
  • [DATA_EXPOSURE]: While the skill mentions authentication and PII fields, it does so in the context of documentation (e.g., asking where credentials are stored or identifying which fields are sensitive). It does not request, store, or transmit any actual sensitive data or credentials.
  • [PROMPT_INJECTION]: No override markers, bypass instructions, or attempts to manipulate the agent's core safety guidelines were detected. The instructional language is standard for a templating task.
  • [INDIRECT_PROMPT_INJECTION]: The skill consumes user-provided input to generate the specification. However, it lacks any exploitable capabilities (such as shell access, file writing, or network operations) that could be triggered by malicious user input, rendering the attack surface benign.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:10 AM
Security Audit — agent-trust-hub — data-pipeline-spec