superset-automate

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the superset CLI tool to list projects and workspaces, and to create, run, and log automations. These are the intended functions of the vendor-provided tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a pattern where automations can read instructions from external documents at runtime to allow for easier editing. This creates a surface for indirect prompt injection if the documents contain untrusted content, though the skill mandates user confirmation and review.
  • Ingestion points: Runtime document reading specified in Step 1 (SKILL.md).
  • Boundary markers: No specific delimiters or safety warnings for the document content are provided in the template.
  • Capability inventory: Scheduled agent prompt execution and logging via the superset automations command set.
  • Sanitization: No explicit sanitization or validation of the external document's content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:38 AM
Security Audit — agent-trust-hub — superset-automate