snowflake-dbt-airbnb-analytics
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from
github.com/analyticsdurgesh/Snowflake_DBT_Project, which is an untrusted external source. - [REMOTE_CODE_EXECUTION]: The skill executes scripts from the cloned repository, such as
scripts/load_inside_airbnb_to_snowflake.pyanddashboard/streamlit_app.py. - [INDIRECT_PROMPT_INJECTION]: The skill ingests raw CSV data from Inside Airbnb into Snowflake for transformation and visualization. If these external datasets contain malicious instructions, they could potentially influence the agent's data processing or analysis logic.
- Ingestion points:
data/raw/directory files loaded viascripts/load_inside_airbnb_to_snowflake.py. - Boundary markers: Absent.
- Capability inventory:
snowflake.connectorfor database operations,dbtfor SQL execution, andstreamlitfor web visualization. - Sanitization: Explicit type casting in dbt models (e.g.,
id::bigint,price::decimal) provides basic data type validation but does not prevent logic-based injection. - [DYNAMIC_EXECUTION]: The skill uses
snowflake.connectorto execute dynamic SQL commands and uses f-strings to construct file paths for staging data, which could lead to command injection if the file paths were user-controlled. - [COMMAND_EXECUTION]: The skill executes various
dbtandstreamlitcommands via the shell to manage the data pipeline and dashboard application.
Recommendations
- AI detected serious security threats
Audit Metadata