bi-measure-builder
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard documentation and patterns for BI developers. It does not contain any hidden or malicious instructions.
- [COMMAND_EXECUTION]: The skill uses a local script
scripts/measure_check.pyto perform verification of measure logic against user data. The script uses thepandaslibrary to process data locally and does not perform any unsafe system operations, network requests, or arbitrary command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided CSV data for calculation verification, which presents a standard attack surface for data-driven skills.
- Ingestion points: User-supplied CSV files and JSON specifications are read by the
measure_check.pyscript. - Boundary markers: The instruction set requires the agent to explicitly define the data model, grain, and evaluation context before generating any code or running tests.
- Capability inventory: Generates BI formula code and executes a local Python verification script.
- Sanitization: Data is processed via standard
pandas.read_csvfunctions without additional sanitization, but the scope is limited to local numerical and date analysis.
Audit Metadata