source-snowflake-query
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by accessing Snowflake credentials (account, user, password) through environment variables rather than hardcoded secrets.
- [COMMAND_EXECUTION]: Input SQL queries are processed through a normalization layer that restricts execution to read-only statements (SELECT, WITH, SHOW, DESCRIBE) and blocks SQL comments or multi-statement queries to prevent injection.
- [DATA_EXFILTRATION]: Network traffic is explicitly constrained to the *.snowflakecomputing.com domain in the skill manifest, ensuring data transport is limited to the intended service.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the standard snowflake-connector-python library for its database operations.
- [PROMPT_INJECTION]: As a data source skill, it handles untrusted rows from external Snowflake tables, representing a potential surface for indirect prompt injection if downstream components process the JSONL output unsafely.
- Ingestion points: Result sets from Snowflake queries in src/ingest.py.
- Boundary markers: Output is emitted as raw JSONL rows; no additional delimiters or instruction-ignore warnings are added to the content.
- Capability inventory: Includes network connectivity to Snowflake and the ability to execute validated SQL queries.
- Sanitization: SQL queries are normalized for read-only safety, and row data is serialized using JSON-safe string conversion.
Audit Metadata