business-intelligence-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture involves ingesting data from external sources to build ETL pipelines and reports, which creates a potential surface for indirect prompt injection.\n
  • Ingestion points: Data enters the system through DataSource configurations and extraction methods described in references/EXAMPLES.md.\n
  • Boundary markers: The provided implementation examples and instructions lack explicit boundary markers or instructions to ignore embedded commands within the processed data.\n
  • Capability inventory: The skill has access to Bash, Write, and WebSearch tools as defined in SKILL.md, which could be targeted by instructions hidden in source data.\n
  • Sanitization: The ETLPipeline logic in references/EXAMPLES.md focuses on data transformation and validation but does not include sanitization or escaping of content to prevent the agent from interpreting data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — business-intelligence-expert