scylladb-docs

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill does not include any executable scripts, binaries, or configuration files. It consists only of markdown instructions and a reference map of documentation links.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for external documentation, which is a potential surface for indirect prompt injection if the source data were malicious.
  • Ingestion points: User queries and external content from official ScyllaDB domains as specified in SKILL.md and references/topic-map.md.
  • Boundary markers: The instructions encourage explicit citations such as "According to ScyllaDB docs..." when answering.
  • Capability inventory: The skill possesses no internal capabilities for file writing, network requests, or command execution; it relies entirely on the agent's native browsing or search tools.
  • Sanitization: None explicit in the skill instructions; it relies on the underlying agent's safety guardrails for processing external text.
  • [SAFE]: The skill references official ScyllaDB documentation hosted on docs.scylladb.com and related subdomains. These are well-known, reputable sources for database documentation, and referencing them is standard functionality for a documentation-focused skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:52 AM
Security Audit — agent-trust-hub — scylladb-docs