postgres-pro
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external SQL queries for optimization purposes (SKILL.md), creating a surface for indirect prompt injection. 1. Ingestion points: SQL query and performance analysis workflow in SKILL.md. 2. Boundary markers: The instructions lack specific delimiters or instructions to the agent to ignore embedded commands within the data. 3. Capability inventory: The skill environment includes high-privilege administrative commands for service control and file system management (references/replication.md). 4. Sanitization: The skill mitigates risks by explicitly instructing the agent to use prepared statements to prevent traditional SQL injection (SKILL.md).
- [COMMAND_EXECUTION]: The skill includes instructions for powerful administrative commands, such as managing system services (
systemctl stop postgresql) and removing directories (rm -rf /var/lib/postgresql/14/main/*), which are standard for database administration but require elevated privileges (references/replication.md).
Audit Metadata