database-schema-agent
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of user-provided domain descriptions and existing repository files (
prisma/schema.prisma). This creates a surface for indirect prompt injection where malicious instructions could be embedded in the data being audited. - Ingestion points: User domain models and
prisma/schema.prismafile content. - Boundary markers: The skill does not explicitly define markers to separate untrusted data from instructions.
- Capability inventory: The skill utilizes the
repo-filestool to write generated schemas and provides instructions for executing shell-based migration commands. - Sanitization: Safety instructions are included to prevent the embedding of production database URLs or passwords, mandating the use of environment variables instead.
Audit Metadata