tracing-upstream-lineage

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides operational guidance for data engineers to trace data origins using the af CLI and source code inspection. All identified operations, such as af dags list, af dags source, and af tasks list, are consistent with the stated purpose of data lineage tracing.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external data (specifically Airflow DAG source code via af dags source in SKILL.md) into the agent's context. While this could theoretically be used as an injection vector if the DAG source code were malicious, it is a necessary part of the skill's primary function and no specific instructions to bypass safety filters are present. The skill currently lacks explicit boundary markers or sanitization for this external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:38 PM
Security Audit — agent-trust-hub — tracing-upstream-lineage