scylladb-docs
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill does not include any executable scripts, binaries, or configuration files. It consists only of markdown instructions and a reference map of documentation links.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for external documentation, which is a potential surface for indirect prompt injection if the source data were malicious.
- Ingestion points: User queries and external content from official ScyllaDB domains as specified in
SKILL.mdandreferences/topic-map.md. - Boundary markers: The instructions encourage explicit citations such as "According to ScyllaDB docs..." when answering.
- Capability inventory: The skill possesses no internal capabilities for file writing, network requests, or command execution; it relies entirely on the agent's native browsing or search tools.
- Sanitization: None explicit in the skill instructions; it relies on the underlying agent's safety guardrails for processing external text.
- [SAFE]: The skill references official ScyllaDB documentation hosted on
docs.scylladb.comand related subdomains. These are well-known, reputable sources for database documentation, and referencing them is standard functionality for a documentation-focused skill.
Audit Metadata