database-schema-designer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected in the skill instructions, scripts, or reference files. All operations are local and perform standard text-based parsing of SQL DDL.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided SQL DDL and natural language requirements. While this provides an attack surface for indirect prompt injection, the risk is categorized as safe because the skill lacks capabilities that could be exploited for harm, such as network exfiltration or system modification.
- Ingestion points: SQL DDL files and natural language requirements provided via the
SKILL.mdtools or agent context. - Boundary markers: Not explicitly defined for tool inputs, though the tools use strict regex-based structural parsing.
- Capability inventory: The skill uses Python scripts (
erd_generator.py,migration_diffr.py,schema_validator.py) to read files and output diagrams/SQL; it does not invoke shells, browsers, or network clients. - Sanitization: Input SQL is parsed for structural elements (tables, columns, indexes) via regular expressions; the input is never executed as code or interpreted as system commands.
Audit Metadata