clickhouse-io
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting data from external PostgreSQL databases into ClickHouse, creating a potential attack surface for indirect prompt injection or data manipulation if source data is malicious. \n
- Ingestion points: Data enters the context through
extractFromPostgres()and PostgreSQL notifications (pgClient.on('notification')) in the ETL and CDC pipeline examples inSKILL.md. \n - Boundary markers: No explicit instructions or delimiters are provided to the agent to treat external data as untrusted or to ignore instructions embedded within the data. \n
- Capability inventory: The skill utilizes
clickhouse.queryandclickhouse.insertto execute database commands based on ingested data. \n - Sanitization: The provided code snippets demonstrate building SQL queries using template literals and string concatenation (
VALUES ${values}) without incorporating data sanitization or parameterized queries, which is a common vulnerability surface.
Audit Metadata