sql-pro

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and optimize user-provided SQL queries, creating a surface for indirect prompt injection where malicious instructions could be embedded in SQL comments or string literals. 1) Ingestion points: User-supplied SQL queries for optimization or troubleshooting (SKILL.md). 2) Boundary markers: The skill lacks specific delimiters or instructions to treat user-provided data as untrusted. 3) Capability inventory: The core workflow involves the agent executing database commands such as 'EXPLAIN ANALYZE' (SKILL.md), which implies access to database tools. 4) Sanitization: The skill provides no mechanisms for validating or escaping user input before analysis.
  • [METADATA_POISONING]: The skill's YAML frontmatter lists 'Jeffallan' as the author via a GitHub link, which conflicts with the identified author 'austin-aziz'. While this is likely an artifact of using a template, the inconsistency represents metadata poisoning.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:06 AM
Security Audit — agent-trust-hub — sql-pro