postgres-pro
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation includes administrative shell commands necessary for PostgreSQL management tasks. Evidence includes instructions for 'systemctl stop postgresql' and 'rm -rf /var/lib/postgresql/14/main/*' in 'references/replication.md', which are standard steps for initializing a standby server via 'pg_basebackup'.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis of external database data such as query execution plans and performance statistics, which represents a potential attack surface for indirect injection. Ingestion points include 'EXPLAIN' analysis and 'pg_stat' view interpretation described in 'references/performance.md' and 'references/maintenance.md'. Boundary markers are not explicitly defined for the interpolation of these data types. The capability inventory includes the generation of high-privilege SQL commands (e.g., 'ALTER', 'DROP', 'VACUUM'). Sanitization is addressed by a specific constraint requiring the use of prepared statements to mitigate SQL injection risks.
Audit Metadata