database-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze data from potentially untrusted sources such as database execution plans, slow query logs, and performance statistics tables.
  • Ingestion points: External data is ingested through commands like EXPLAIN ANALYZE and by reading performance tables such as pg_stat_statements or MySQL's performance_schema (detailed in SKILL.md and references/monitoring-analysis.md).
  • Boundary markers: The instructions do not define clear boundaries or provide warnings to the agent about ignoring potential instructions embedded in the query strings it analyzes.
  • Capability inventory: The skill provides the agent with templates for high-privilege operations, including modifying system settings (ALTER SYSTEM), managing indexes, and performing full table vacuums (detailed in references/postgresql-tuning.md and references/mysql-tuning.md).
  • Sanitization: There is no mention of filtering or sanitizing the database output before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — database-optimizer