setting-up-data-catalog

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses specific vendor tools (prefixed with posthog:) to interact with the project's data warehouse and catalog system. Access is restricted to the PostHog environment.
  • [SAFE]: Mitigation of Indirect Prompt Injection: The instructions explicitly command the agent to treat free text (descriptions, notes, reasoning) read from the database as data and never as instructions, reducing the risk of data-driven attacks.
  • [SAFE]: Human-in-the-loop: Critical administrative actions such as metric promotion, source certification, and join acceptance require explicit human confirmation via confirmed_action tools.
  • [SAFE]: Principle of Least Privilege: The skill documentation clarifies that the catalog describes existing data and never copies it, minimizing data exposure risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 03:59 PM
Security Audit — agent-trust-hub — setting-up-data-catalog