bigquery-agent-analytics-sdk

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes AI agent execution traces, including user inputs and agent outputs, from BigQuery datasets. These untrusted traces are evaluated by an LLM-based judge (LLMAsJudge) using models like gemini-2.0-flash-exp. This architecture presents an indirect prompt injection surface where malicious content embedded in the agent traces could potentially manipulate the judge's scoring or behavior.
  • Ingestion points: client.get_traces(), client.get_trace(), and SQL results from client.query() in SKILL.md.
  • Capability inventory: LLMAsJudge (performs external model calls), client.query() (executes arbitrary SQL on BigQuery).
  • Boundary markers: No explicit delimiters or boundary warnings are shown in the prompts sent to the judge components.
  • Sanitization: The examples do not demonstrate sanitization or filtering of trace content before evaluation.
  • [COMMAND_EXECUTION]: The documentation describes the use of shell pipelines, such as envsubst < table_ddl.sql | bq query, to initialize database schemas and manage configuration variables via the command line.
  • [PRIVILEGE_ESCALATION]: The bqaa CLI tool provides functionality to deploy cloud infrastructure, specifically Cloud Run services and Cloud Scheduler jobs (bqaa schedule-context-graph). Utilizing these features requires high-level IAM permissions, such as Service Account User and Cloud Run Developer roles.
  • [PERSISTENCE]: The skill facilitates the creation of persistent execution triggers in the cloud by configuring Cloud Scheduler (Cron) jobs through the bqaa schedule-context-graph command, enabling recurring analysis tasks.
  • [DYNAMIC_EXECUTION]: The SDK supports dynamic SQL construction via the InsightsPipeline and client.query() methods. It also allows the use of Python lambda functions for custom data extraction logic during the ContextGraph materialization process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — bigquery-agent-analytics-sdk