diagnosing-failed-warehouse-syncs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted 'latest_error' strings from external data sources to determine diagnostic outcomes and recommend recovery actions.
  • Ingestion points: Error message content is ingested from external services via tools such as 'external-data-sources-retrieve' and 'external-data-schemas-list'.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the content of external error messages.
  • Capability inventory: The skill includes access to destructive tools like 'external-data-schemas-resync' and 'external-data-schemas-delete-data', as well as tools for updating source credentials.
  • Sanitization: While no technical sanitization of error strings is defined, the skill includes a significant mitigation in Step 5, which mandates explicit human confirmation before executing any destructive action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:31 PM
Security Audit — agent-trust-hub — diagnosing-failed-warehouse-syncs