snowflake-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from Snowflake environments (such as table metadata, query history, and data streams) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The agent is instructed to analyze and manage user-specified architecture, database objects, and query logs (SKILL.md).
- Boundary markers: There are no instructions defining clear boundaries or "ignore embedded instructions" protocols for data retrieved from Snowflake or provided by the user.
- Capability inventory: The skill allows access to the
Bashtool and file system modification tools (Write,Edit), which could be leveraged if an injection attack is successful (SKILL.md frontmatter). - Sanitization: The instructions do not prescribe any sanitization or validation steps for content retrieved from external data sources before the agent acts upon it.
Audit Metadata