business-intelligence-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture involves ingesting data from external sources to build ETL pipelines and reports, which creates a potential surface for indirect prompt injection.\n
- Ingestion points: Data enters the system through
DataSourceconfigurations and extraction methods described inreferences/EXAMPLES.md.\n - Boundary markers: The provided implementation examples and instructions lack explicit boundary markers or instructions to ignore embedded commands within the processed data.\n
- Capability inventory: The skill has access to
Bash,Write, andWebSearchtools as defined inSKILL.md, which could be targeted by instructions hidden in source data.\n - Sanitization: The
ETLPipelinelogic inreferences/EXAMPLES.mdfocuses on data transformation and validation but does not include sanitization or escaping of content to prevent the agent from interpreting data as instructions.
Audit Metadata