database-schema-agent

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of user-provided domain descriptions and existing repository files (prisma/schema.prisma). This creates a surface for indirect prompt injection where malicious instructions could be embedded in the data being audited.
  • Ingestion points: User domain models and prisma/schema.prisma file content.
  • Boundary markers: The skill does not explicitly define markers to separate untrusted data from instructions.
  • Capability inventory: The skill utilizes the repo-files tool to write generated schemas and provides instructions for executing shell-based migration commands.
  • Sanitization: Safety instructions are included to prevent the embedding of production database URLs or passwords, mandating the use of environment variables instead.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:02 AM
Security Audit — agent-trust-hub — database-schema-agent