skills/celeroncoder/dbm/dbm-cli/Gen Agent Trust Hub

dbm-cli

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download a global package artifact from the author's GitHub releases at https://github.com/celeroncoder/dbm/releases/download/v0.1.1/celeroncoder-dbm-0.1.1.tgz.
  • [REMOTE_CODE_EXECUTION]: Installs and executes a remote package artifact using the global bun add command from the author's repository.
  • [COMMAND_EXECUTION]: Instructs the agent to run multiple management and testing commands using bun (e.g., bun install, bun run dev, bun run check, bun run verify:docker) and interacts with various native database clients.
  • [PRIVILEGE_ESCALATION]: Uses non-interactive sudo -n docker as a fallback mechanism to handle Docker socket permission errors when the engine is not otherwise accessible.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads and displays data retrieved from database clients (psql, mysql, redis-cli, mongosh) and container logs in the terminal UI.
  • Boundary markers: Not explicitly mentioned in the skill text.
  • Capability inventory: Includes command execution through Bun and infrastructure management through Docker (start, stop, pause, remove).
  • Sanitization: No specific sanitization or filtering of database output is detailed in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 09:12 AM
Security Audit — agent-trust-hub — dbm-cli