tracing-upstream-lineage
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides operational guidance for data engineers to trace data origins using the
afCLI and source code inspection. All identified operations, such asaf dags list,af dags source, andaf tasks list, are consistent with the stated purpose of data lineage tracing. - [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external data (specifically Airflow DAG source code via
af dags sourcein SKILL.md) into the agent's context. While this could theoretically be used as an injection vector if the DAG source code were malicious, it is a necessary part of the skill's primary function and no specific instructions to bypass safety filters are present. The skill currently lacks explicit boundary markers or sanitization for this external content.
Audit Metadata