data-model-creation
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided business entities and requirements to generate data models, creating a potential surface for indirect prompt injection if external data is included in the user's request.
- Ingestion points: User business descriptions and entity names are processed in SKILL.md to create Mermaid classDiagrams.
- Boundary markers: None explicitly defined in the provided instruction set to delimit user-provided data from system instructions.
- Capability inventory: The skill uses
manageDataModelandmodifyDataModeltools to interact with database schemas. - Sanitization: The skill enforces strict naming conventions (PascalCase for classes, camelCase for fields) and a mapping table for types, which provides a degree of normalization for external input.
Audit Metadata