sql-expert
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external databases, creating a surface for indirect prompt injection if the database content is attacker-controlled. \n
- Ingestion points: The agent reads database schema metadata and query results via
DatabaseHelper.get_table_schemaandDatabaseHelper.execute_with_timinginscripts/sql_helper.py. \n - Boundary markers: There are no explicit instructions or delimiters defined to separate retrieved database data from the agent's internal control logic. \n
- Capability inventory: The skill possesses high-privilege capabilities including the execution of arbitrary SQL commands (SELECT, INSERT, UPDATE, DELETE, etc.) through the
DatabaseHelperclass. \n - Sanitization: Although the helper script promotes the use of parameterized queries via SQLAlchemy's
text()interface, there is no validation or sanitization of the data retrieved from the database before it enters the agent's context.
Audit Metadata