ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Databricks Genie: Malicious Skill Slips Past Four Controls to Phish and Exfiltrate Data

Databricks Genie: Malicious Skill Slips Past Four Controls to Phish and Exfiltrate Data

AI information • Admin • • 17 views

Databricks Genie's chat rendering feature was turned into a data exfiltration channel by a malicious Skill. On October 5, 2026, security firm PromptArmor published a disclosure report: after Databricks' agentic assistant Genie Code runs a malicious Skill, it shows a phishing window when the user opens the analysis results, and uses the user's own browser to send tenant data to an attacker's server. Four categories of controls that enterprises counted on to catch this stopped none of it. To be clear about what this is: it is a researched attack demonstration published through a responsible disclosure process, not a confirmed real-world data breach.

How the attack runs, step by step

Genie Code is Databricks' agentic assistant for enterprise data teams, letting users operate on data in their tenant through natural language. Databricks has been expanding aggressively — on one recent model launch day, Databricks had 12,000 employees testing it. The attack chain PromptArmor demonstrated has four steps:

  1. A user asks Genie to analyze data using an uploaded Skill. Skills circulate through online marketplaces, an ecosystem already polluted with malicious Skills, and Genie loads Skills from users' personal workspaces rather than the organization's governed catalog.
  2. Genie executes the code in the Skill. A guardrail agent reviews commands before they run and flags actions such as "sending data to third parties," but this time it approved the code and missed the malicious capability hidden inside.
  3. Genie prompts the user to open the full analysis results.
  4. The moment the results render, the attack fires on two fronts: the Skill's code has already embedded sensitive information it collected from the tenant, such as the victim's datasets, into an HTML display; scripts in that display make the user's browser send network requests that carry the data to the attacker's server. At the same time, the display overlays a phishing page that tricks the user into handing over credentials. No human-in-the-loop approval is involved at any point.

Why none of the four controls stopped it

  • Organization-level Skill governance: Databricks has a governed catalog system, but Genie actually loads Skills from personal workspaces, a layer the governance never reaches.
  • The guardrail agent: Databricks says its auto-allow functionality is not intended as a security boundary, only as a control measure to prevent untrusted input from running automatically — yet it is also the documented default and recommended command approval mode. Expecting it to act as a security review is expecting the wrong thing from it.
  • Coding-environment egress controls: the coding environment is indeed barred from contacting untrusted external parties, and that rule was never broken. The requests were issued by the user's browser, an egress path the coding environment's controls do not cover.
  • Sandboxing of rendered displays: the rules say a display may not query data from the tenant, and that too was technically upheld — the display queried nothing. It simply rendered data the Skill's code had embedded in it beforehand, and sent that data out.

PromptArmor's conclusion: two guarantees were technically upheld, yet the very outcome they existed to prevent — data exfiltration — still happened, which points to a gap in Databricks' threat model.

Databricks' response, and the one point it did not address

The timeline is explicit: PromptArmor reported the issue to Databricks on August 16, 2026; the two sides coordinated until September 15; on September 16, PromptArmor gave notice that it would publish. Databricks' core response was that "it is ultimately the user's responsibility to ensure that uploaded skills do not contain malicious content." On the fact that Genie loads Skills from personal workspaces instead of the organization-level governed catalog, Databricks offered no statement.

What teams running Genie should do now

First, treat Skills in personal workspaces as code: do not install Skills from unknown sources, and review them before use. Second, disable or tighten auto-allow in production data environments, and accept more approval interruptions. Third, extend monitoring to browser-side egress — the lesson here is that data does not have to leave through the server; it can leave through an employee's browser. Fourth, inventory every Skill already installed and where it came from. The risk is not unique to Databricks: any product that lets an agent render HTML in chat while third-party Skills can touch business data should test itself against the same attack chain.

Recommended Tools

More