clickhouse-best-practices
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of Markdown documentation files that provide technical guidance for ClickHouse users. It does not contain any executable scripts, binaries, or configuration files that perform system operations.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths (such as SSH keys or environment files) were found in any of the files. All external references are directed toward official ClickHouse documentation domains.
- [REMOTE_CODE_EXECUTION]: There are no patterns suggesting the download or execution of remote code. The skill does not use tools like curl, wget, or package managers to fetch external scripts at runtime.
- [PROMPT_INJECTION]: The instructions provided to the agent are focused on rule application and response formatting. No attempts to bypass safety filters, extract system prompts, or override agent constraints were detected.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided SQL schemas and queries, it lacks capabilities that could be exploited via indirect injection, such as shell command execution or network exfiltration. The risk is limited to the accuracy of the advice provided.
- [OBFUSCATION]: All content is in plain text. No Base64, hex encoding, zero-width characters, or other obfuscation techniques were used to hide malicious payloads.
Audit Metadata