data-mesh-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an architecture consultant, creating a surface for indirect prompt injection via the processing of untrusted architectural specifications.\n
- Ingestion points: The agent is designed to ingest and interpret domain designs and data product specifications provided by the user, as described in SKILL.md and references/CORE_CONCEPTS.md.\n
- Boundary markers: No explicit delimiters or boundary instructions are present to distinguish user-provided data from system instructions during the processing of external specifications.\n
- Capability inventory: The skill utilizes high-privilege tools including Bash, Write, and Edit. Reference code in references/CORE_CONCEPTS.md demonstrates a pattern of generating Airflow DAGs (Python scripts) that interpolate user-provided identifiers (spec.name) directly into shell commands via BashOperator.\n
- Sanitization: The illustrative code examples do not include sanitization or validation of input identifiers, which could lead to command injection vulnerabilities if the agent follows these patterns to generate or deploy infrastructure code.
Audit Metadata