clickhouse-js-node-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides detailed documentation and troubleshooting steps for the @clickhouse/client Node.js library, including specific guidance for different client versions.
  • [PROMPT_INJECTION]: No prompt injection, DAN, or system prompt extraction patterns were found. The instructions are focused on guiding the agent to provide accurate troubleshooting.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. Examples use placeholders like 'secret', '', and '' for configuration.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. Examples that read files (e.g., fs.readFileSync for TLS certificates) are standard practice for client-side secure connection configuration.
  • [EXTERNAL_DOWNLOADS]: All external references target official ClickHouse documentation and their official GitHub repository. No remote scripts or unverified dependencies are introduced.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill includes a curl command for connection triage, which is a standard diagnostic tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided error logs and symptoms to provide diagnosis. While this involves processing external data, the skill is designed for troubleshooting and contains specific advice on preventing SQL injection via parameterized queries, mitigating risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:01 PM
Security Audit — agent-trust-hub — clickhouse-js-node-troubleshooting