altinity-expert-clickhouse-security
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for read-only security auditing of ClickHouse systems. It explicitly forbids destructive operations and provides clear rules for redacting sensitive information like password hashes and API keys.
- [PROMPT_INJECTION]: The skill evaluates database logs and table metadata, which are sources of untrusted data, creating an indirect prompt injection surface. This is an inherent risk in auditing tools and is mitigated by the skill's instructions to maintain a senior security reviewer persona and avoid non-audit operations. Ingestion points: system.query_log, system.tables, and user-supplied configuration files. Boundary markers: Not present. Capability inventory: Read-only SQL metadata inspection. Sanitization: Mandatory redaction of secrets in report output.
Audit Metadata