dbt-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis and processing of user-supplied dbt projects and SQL code. This ingestion path presents a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to interact with dbt configuration files (e.g., dbt_project.yml, profiles.yml), SQL models, and Jinja templates provided in the user's workspace.
  • Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish its core instructions from potentially adversarial content embedded in user files.
  • Capability inventory: The agent has access to powerful tools such as Bash, Write, and Edit. These could be exploited if the agent follows malicious instructions found within a user-controlled dbt project (e.g., within Jinja macros or dbt hooks).
  • Sanitization: There are no defined procedures for validating or sanitizing user-provided SQL or Jinja code before it is processed by the agent or potentially executed via the command line.
  • [EXTERNAL_DOWNLOADS]: The reference documentation includes examples of external dependencies, specifically fetching dbt packages from the official repository of a well-known analytics engineering organization on GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:41 PM
Security Audit — agent-trust-hub — dbt-expert