sql-expert

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external databases, creating a surface for indirect prompt injection if the database content is attacker-controlled. \n
  • Ingestion points: The agent reads database schema metadata and query results via DatabaseHelper.get_table_schema and DatabaseHelper.execute_with_timing in scripts/sql_helper.py. \n
  • Boundary markers: There are no explicit instructions or delimiters defined to separate retrieved database data from the agent's internal control logic. \n
  • Capability inventory: The skill possesses high-privilege capabilities including the execution of arbitrary SQL commands (SELECT, INSERT, UPDATE, DELETE, etc.) through the DatabaseHelper class. \n
  • Sanitization: Although the helper script promotes the use of parameterized queries via SQLAlchemy's text() interface, there is no validation or sanitization of the data retrieved from the database before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:47 AM
Security Audit — agent-trust-hub — sql-expert