backend-migrate

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from migration directories and project memory files.
  • Ingestion points: Migration files located via glob patterns in 'migrations/', 'db/migrate/', 'prisma/migrations/', 'alembic/versions/', and 'src/main/resources/db/migration/', plus '.opencode/everything-backend-memory/db-schema.md'.
  • Boundary markers: The skill lacks explicit markers or instructions to isolate instructions from the data within these files.
  • Capability inventory: The skill facilitates SQL generation and modification of project files like 'db-schema.md' and 'decisions.md'.
  • Sanitization: No sanitization or validation of the content of the migration files is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:46 AM
Security Audit — agent-trust-hub — backend-migrate