create-readonly-db-role
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a verification workflow that interpolates untrusted user input into shell commands, creating a potential command injection surface.
- Ingestion points: User-provided values for the
<readonly-connection-url>placeholder and various table name placeholders in the verification scripts withinSKILL.md. - Boundary markers: Absent. The instructions do not define delimiters or provide 'ignore' instructions for the untrusted data being interpolated into the shell context.
- Capability inventory: Shell command execution via the
psqlCLI utility as documented in theVerificationsection ofSKILL.md. - Sanitization: Absent. The skill provides no guidance or requirements for escaping or validating user-supplied connection strings before they are passed to the shell.
- [COMMAND_EXECUTION]: The skill contains explicit instructions for the agent to execute shell commands using the
psqlutility to perform system-level database checks. - [DYNAMIC_EXECUTION]: The verification process involves the dynamic assembly of shell commands by concatenating fixed command strings with runtime user input, a pattern that requires strict sanitization.
Audit Metadata