data-metabase

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external API responses that could contain malicious instructions.
  • Ingestion points: The agent ingests data from Metabase API responses through scripts/metabase_api.py, including query results, card definitions, and metadata.
  • Boundary markers: The instructions do not define boundary markers or delimiters to separate the ingested data from the agent's reasoning process.
  • Capability inventory: The skill uses scripts/metabase_api.py, which has capabilities for file writing (_write_json, _write_bytes) and network operations via urllib.request.
  • Sanitization: There are no instructions for sanitizing, validating, or escaping the data fetched from the Metabase API before the agent acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — data-metabase