clickhouse-io

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily educational, providing SQL and TypeScript examples for ClickHouse database management.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The code correctly demonstrates the use of environment variables (process.env) for sensitive information like database URLs and passwords, which is a recommended security practice.
  • [EXTERNAL_DOWNLOADS]: No suspicious external downloads or remote script executions were identified. The skill references standard libraries such as 'clickhouse' and 'pg'.
  • [DATA_EXFILTRATION]: No patterns of unauthorized data access or exfiltration to untrusted domains were detected. Network operations are limited to standard database connections as defined by the user's environment configuration.
  • [COMMAND_EXECUTION]: No dangerous system command executions, privilege escalation attempts, or persistence mechanisms were found.
  • [PROMPT_INJECTION]: The skill contains no instructions designed to bypass AI safety guidelines or override system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — clickhouse-io