data-lake-platform

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides procedures for downloading and inspecting data lake metadata. For instance, scripts/inspect_iceberg_metadata.sh downloads metadata.json and manifest files from S3 or GCS using standard CLI tools (aws, gsutil) to analyze table layouts. It also guides the user to clone well-known repositories such as Airbyte.
  • [COMMAND_EXECUTION]: Orchestration templates demonstrate the use of subprocess.run to interact with CLI tools like sqlmesh and dlt. The management script scripts/inspect_iceberg_metadata.sh uses localized shell commands for data processing (jq, awk, sort). These executions are transparent and typical for data engineering workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a significant surface for indirect prompt injection by design, as its primary role is ingesting and transforming data from external systems.
  • Ingestion points: Data enters the agent's context via REST APIs and SQL databases as shown in assets/ingestion/dlt/template-dlt-rest-api.md and assets/ingestion/dlt/template-dlt-database-source.md.
  • Boundary markers: While the code templates do not use explicit delimiters, the skill provides extensive documentation on data contracts and quality standards in references/data-mesh-patterns.md.
  • Capability inventory: The skill utilizes capabilities for shell execution (subprocess.run), network operations (database connectors, aws/gsutil CLI), and filesystem access.
  • Sanitization: The skill includes extensive templates and documentation for implementing data quality gates using tools like Great Expectations and Soda (references/data-quality-patterns.md) to validate and sanitize external content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — data-lake-platform