altimate-data-engineering-skills
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation describes a delegation mechanism that invokes
altimate-code run --yolo. The use of a non-interactive/"yolo" flag for executing complex data tasks reduces user oversight and bypasses typical confirmation steps during agent-led operations. - Evidence: SKILL.md mentions:
Invokes altimate-code run --yolo non-interactively. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of external CLI tools and plugins from GitHub and NPM registries to function correctly.
- Evidence: Instructions include
npm install -g altimate-code,git clone https://github.com/AltimateAI/data-engineering-skills.git, and/plugin installcommands for various sub-skills. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting untrusted external data such as database error messages and query profiles which then influence the agent's file-writing and build actions.
- Ingestion points:
SKILL.md(debugging-dbt-errors skill reads full error messages; optimizing-query-by-id retrieves query profiles). - Boundary markers: None explicitly defined in the provided instruction set to delimit external data from agent instructions.
- Capability inventory: The skill can write files (creating dbt models), execute shell commands (
dbt build,dbt show), and delegate to thealtimate-codeCLI. - Sanitization: No sanitization or validation logic is mentioned for the external error messages or query data before processing.
Audit Metadata