gcp-bigquery
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of BigQuery AI functions like
AI.GENERATE,AI.GENERATE_BOOL, andAI.SIMILARITY. These functions process data from table columns (e.g.,review_text,description) directly through LLMs (Gemini). If these columns contain attacker-controlled content, they represent a surface for indirect prompt injection. The severity is LOW as this is an inherent risk of the documented capability rather than a flaw in the skill itself.
Audit Metadata