source-snowflake-query

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by accessing Snowflake credentials (account, user, password) through environment variables rather than hardcoded secrets.
  • [COMMAND_EXECUTION]: Input SQL queries are processed through a normalization layer that restricts execution to read-only statements (SELECT, WITH, SHOW, DESCRIBE) and blocks SQL comments or multi-statement queries to prevent injection.
  • [DATA_EXFILTRATION]: Network traffic is explicitly constrained to the *.snowflakecomputing.com domain in the skill manifest, ensuring data transport is limited to the intended service.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the standard snowflake-connector-python library for its database operations.
  • [PROMPT_INJECTION]: As a data source skill, it handles untrusted rows from external Snowflake tables, representing a potential surface for indirect prompt injection if downstream components process the JSONL output unsafely.
  • Ingestion points: Result sets from Snowflake queries in src/ingest.py.
  • Boundary markers: Output is emitted as raw JSONL rows; no additional delimiters or instruction-ignore warnings are added to the content.
  • Capability inventory: Includes network connectivity to Snowflake and the ability to execute validated SQL queries.
  • Sanitization: SQL queries are normalized for read-only safety, and row data is serialized using JSON-safe string conversion.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:18 AM
Security Audit — agent-trust-hub — source-snowflake-query