db-migration-inception
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external databases during the inventory phase, which could contain adversarial content in schema names or stored code.
- Ingestion points: The dbmig inventory command reads schema metadata (tables, datatypes, stored-code) from the source database defined in connections.yaml (Step 2).
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the ingested schema data as untrusted or to ignore instructions embedded within stored code.
- Capability inventory: The skill executes shell commands (pip, python) and has write access to the filesystem to generate assessment artifacts (Step 1, Step 2, Step 5).
- Sanitization: There is no mention of sanitizing or escaping database object names or code content before the agent evaluates them for compatibility.
- [COMMAND_EXECUTION]: The skill utilizes the shell to manage dependencies and execute the migration analysis tool via python -m dbmig (Step 1, Step 2).
- [EXTERNAL_DOWNLOADS]: The skill performs an automated installation of Python packages from a local requirements file (pip install -r scripts/requirements.txt) which may fetch external dependencies during the setup phase (Step 1).
- [CREDENTIALS_UNSAFE]: The skill reads from connections.yaml, which is the designated storage for database connection strings and credentials necessary for assessing the source environment.
Audit Metadata