data-metabase
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external API responses that could contain malicious instructions.
- Ingestion points: The agent ingests data from Metabase API responses through
scripts/metabase_api.py, including query results, card definitions, and metadata. - Boundary markers: The instructions do not define boundary markers or delimiters to separate the ingested data from the agent's reasoning process.
- Capability inventory: The skill uses
scripts/metabase_api.py, which has capabilities for file writing (_write_json,_write_bytes) and network operations viaurllib.request. - Sanitization: There are no instructions for sanitizing, validating, or escaping the data fetched from the Metabase API before the agent acts upon it.
Audit Metadata