serving-schema-review
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes explicit instructions and evaluation cases that teach the agent how to identify and disregard malicious prompt injection attempts (such as 'ignore previous instructions') embedded within schema comments or metadata. These are defensive guidelines and do not constitute an attempt to bypass system behaviors.
- [EXTERNAL_DOWNLOADS]: Reference documentation includes links to well-known technology platforms and official technical guides (e.g., Microsoft Learn, Databricks, GitLab) for informational purposes. These references do not involve remote code execution or interaction with untrusted sources.
- [CREDENTIALS_UNSAFE]: The skill mandates safe handling of sensitive data by instructing the agent to flag potential credentials found in user-provided schemas as security findings rather than echoing them back to the user. This is a positive security implementation.
- [PROMPT_INJECTION]: The skill is designed to process untrusted schema artifacts (DDL, ERD) and includes boundary instructions and sanitization rules to mitigate the risk of indirect prompt injection.
Audit Metadata