stream
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting external data, including model contracts from the 'Schema' agent and KPI requirements from the 'Pulse' agent, to architect data pipelines. This design-centric workflow creates an attack surface where malicious instructions could be embedded within structured metadata, schemas, or metric definitions to influence the agent's output or be incorporated into implementation packets.
- Ingestion points: Requirements and data contracts ingested from 'Schema' and 'Pulse' agents as described in the 'Trigger Guidance' and 'Collaboration' sections of SKILL.md.
- Boundary markers: The skill emphasizes the use of explicit data contracts and quality gates (documented in reference/data-quality.md) and mandates a handoff to the 'Sentinel' agent for security reviews.
- Capability inventory: The skill generates architectural designs for systems with broad capabilities, including file system management (dbt), network-based event streaming (Kafka/CDC), and task orchestration (Airflow/Dagster), as detailed across the reference files.
- Sanitization: The instructions explicitly require PII handling strategies and security review checkpoints to mitigate risks associated with processing sensitive or untrusted data.
Audit Metadata