setting-up-data-catalog
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses specific vendor tools (prefixed with
posthog:) to interact with the project's data warehouse and catalog system. Access is restricted to the PostHog environment. - [SAFE]: Mitigation of Indirect Prompt Injection: The instructions explicitly command the agent to treat free text (descriptions, notes, reasoning) read from the database as data and never as instructions, reducing the risk of data-driven attacks.
- [SAFE]: Human-in-the-loop: Critical administrative actions such as metric promotion, source certification, and join acceptance require explicit human confirmation via
confirmed_actiontools. - [SAFE]: Principle of Least Privilege: The skill documentation clarifies that the catalog describes existing data and never copies it, minimizing data exposure risks.
Audit Metadata