analytical-databases-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to use tools like DuckDB and ClickHouse to query data from external sources, including Parquet files, S3 buckets, and existing databases. This processing of potentially untrusted external data, combined with access to system-level tools, creates an attack surface for instructions embedded in the data to influence agent behavior.
  • Ingestion points: SKILL.md and references/MODELLING.md contain patterns for read_parquet, postgres_scan, and ATTACH which load external data into the processing environment.
  • Boundary markers: The provided code templates do not include specific delimiters or instructions to ignore potential commands within the ingested data.
  • Capability inventory: The skill environment permits the use of Bash (with access to python, pip, duckdb, clickhouse-client, and docker) alongside Read, Write, and Edit file system tools.
  • Sanitization: No explicit sanitization or input validation logic is described for handling external data content.
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of DuckDB's extension manager to install additional functionality (e.g., INSTALL postgres; LOAD postgres;). This triggers the download of binary files from DuckDB's official distribution infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — analytical-databases-expert