db-migration-inception

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external databases during the inventory phase, which could contain adversarial content in schema names or stored code.
  • Ingestion points: The dbmig inventory command reads schema metadata (tables, datatypes, stored-code) from the source database defined in connections.yaml (Step 2).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the ingested schema data as untrusted or to ignore instructions embedded within stored code.
  • Capability inventory: The skill executes shell commands (pip, python) and has write access to the filesystem to generate assessment artifacts (Step 1, Step 2, Step 5).
  • Sanitization: There is no mention of sanitizing or escaping database object names or code content before the agent evaluates them for compatibility.
  • [COMMAND_EXECUTION]: The skill utilizes the shell to manage dependencies and execute the migration analysis tool via python -m dbmig (Step 1, Step 2).
  • [EXTERNAL_DOWNLOADS]: The skill performs an automated installation of Python packages from a local requirements file (pip install -r scripts/requirements.txt) which may fetch external dependencies during the setup phase (Step 1).
  • [CREDENTIALS_UNSAFE]: The skill reads from connections.yaml, which is the designated storage for database connection strings and credentials necessary for assessing the source environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:18 AM