zomato-ai-data-engineering-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a codebase from a third-party GitHub repository.
  • Evidence: git clone https://github.com/darshilparmar/zomato-ai-data-engineering-end-to-end-project in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted restaurant review data by interpolating it directly into LLM prompts for sentiment analysis and RAG (Retrieval-Augmented Generation).
  • Ingestion points: RAW.REVIEWS table in Snowflake (processed in ai/enrich_reviews.py and ai/rag_chat.py).
  • Boundary markers: Minimal. Uses simple string interpolation (f-strings) to insert review text into prompts.
  • Capability inventory: The agent has the ability to write to Snowflake tables and call external LLM APIs.
  • Sanitization: None. The skill directly passes review_text into the prompt.
  • [COMMAND_EXECUTION]: The skill uses BashOperator and PythonOperator within Airflow to execute dbt commands and custom Python scripts.
  • Evidence: dbt build commands and enrich_reviews() function calls in the Airflow DAG definition in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — zomato-ai-data-engineering-pipeline