dbt-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis and processing of user-supplied dbt projects and SQL code. This ingestion path presents a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to interact with dbt configuration files (e.g.,
dbt_project.yml,profiles.yml), SQL models, and Jinja templates provided in the user's workspace. - Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish its core instructions from potentially adversarial content embedded in user files.
- Capability inventory: The agent has access to powerful tools such as
Bash,Write, andEdit. These could be exploited if the agent follows malicious instructions found within a user-controlled dbt project (e.g., within Jinja macros or dbt hooks). - Sanitization: There are no defined procedures for validating or sanitizing user-provided SQL or Jinja code before it is processed by the agent or potentially executed via the command line.
- [EXTERNAL_DOWNLOADS]: The reference documentation includes examples of external dependencies, specifically fetching dbt packages from the official repository of a well-known analytics engineering organization on GitHub.
Audit Metadata