creating-mermaid-dbt-dag

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from dbt project files (manifest.json, SQL models, Python models, and YAML configurations) which are considered untrusted sources.
  • Ingestion points: Data is ingested through the Read, Glob, and Grep tools when accessing manifest.json and model files in the models/ or seeds/ directories.
  • Boundary markers: The skill contains a dedicated 'Handling External Content' section that explicitly warns the agent to ignore any instructions or commands embedded within these files.
  • Capability inventory: The skill uses the Read, Glob, Grep, and Bash(jq *) tools for data retrieval and extraction. It does not possess capabilities for network exfiltration or modifying critical system files.
  • Sanitization: The instructions require the agent to extract only specific structured metadata (unique identifiers, resource types, and file paths) while ignoring any natural language instructions found in the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:37 PM
Security Audit — agent-trust-hub — creating-mermaid-dbt-dag