interpolated-database-query

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The build_query function in query.py implements an unsafe string interpolation pattern to construct database queries, making it vulnerable to injection attacks.
  • Ingestion points: The user_id parameter in the build_query function (query.py) serves as the ingestion point for untrusted, caller-controlled data.
  • Boundary markers: The skill lacks any boundary markers or delimiters to separate the user-provided data from the SQL command structure, allowing for command confusion.
  • Capability inventory: The skill is specifically designed to generate database query strings. While it does not execute them internally, it creates the capability for downstream tools to execute potentially malicious SQL.
  • Sanitization: There is no evidence of input validation, sanitization, or the use of parameterized queries (prepared statements). The code uses Python f-strings to directly embed the user_id into the query string.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — interpolated-database-query