realtime-cinema-data-engineering-pipeline
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill contains hardcoded default credentials for the local PostgreSQL database.
- Evidence:
POSTGRES_USER=postgres,POSTGRES_PASSWORD=postgres, andAIRFLOW_CONN_POSTGRES_CINEMA_DW=postgresql://postgres:postgres@postgres:5432/cinema_dwin the environment configuration section. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone code from an untrusted repository.
- Evidence:
git clone https://github.com/BaidaneAyoub/realtime-cinema-data-engineering.gitin the Setup Steps. - [COMMAND_EXECUTION]: The instructions include commands to install and execute the downloaded external code.
- Evidence:
pip install -r requirements.txt,python producer/main_producer.py,python consumer/main_consumer.py, andstreamlit run dashboard/app.py. - [INDIRECT_PROMPT_INJECTION]: The pipeline ingests untrusted data from a Kafka stream which is then processed by an Airflow ELT pipeline.
-
- Ingestion points:
consumer/main_consumer.pyreads events from thecinema_transactionsKafka topic.
- Ingestion points:
-
- Boundary markers: None identified; data is parsed as raw JSON.
-
- Capability inventory: The skill performs database writes to the Bronze and Silver layers and executes transformations via Airflow PythonOperators.
-
- Sanitization: No explicit sanitization or validation of the ingested JSON payload structure before processing.
Audit Metadata