monte-carlo-prevent
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts for dbt project analysis and runs the
dbt buildcommand to materialize models in a sandbox environment. These operations are core to the skill's functionality and include user confirmation prompts before execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, including the Monte Carlo API (alerts, lineage, monitors) and local dbt project files (.sql and .yml). This data is used to generate change impact assessments and validation queries. The skill mitigates risks through explicit synthesis instructions and mandatory human-in-the-loop review checkpoints before any code is modified or executed.
- Ingestion points: Monte Carlo API tool outputs (
getAlerts,getAssetLineage), local dbt model files, andprofiles.ymlconfiguration. - Boundary markers: The agent is instructed to synthesize findings into specific recommendations and present them to the user for approval.
- Capability inventory: Execution of
dbt buildand SQL execution via a Snowflake MCP server. - Sanitization: SQL execution is protected by
readonly_check.py, which validates for write-like keywords, andclassify_sandbox.py, which prevents execution against production databases. - [DYNAMIC_EXECUTION]: The skill generates SQL validation queries by substituting environment-specific placeholders in generated templates. These queries are then executed via a Snowflake MCP server. Security is maintained by a mandatory read-only keyword check and by displaying the final SQL to the user for confirmation prior to execution.
Audit Metadata