dbt-migration-snowflake

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection because its primary function is to ingest and transform external Snowflake DDL provided by the user.
  • Ingestion points: User-provided Snowflake DDL input in the conversion workflow.
  • Boundary markers: The instructions lack specific delimiting markers or instructions to treat input data as strictly non-executable text.
  • Capability inventory: The skill generates SQL and YAML files for dbt projects but does not directly invoke system shell commands, network operations, or file-writing tools.
  • Sanitization: No input validation or sanitization rules for the Snowflake DDL are specified in the conversion guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:59 PM
Security Audit — agent-trust-hub — dbt-migration-snowflake