clickhouse-io

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting data from external PostgreSQL databases into ClickHouse, creating a potential attack surface for indirect prompt injection or data manipulation if source data is malicious. \n
  • Ingestion points: Data enters the context through extractFromPostgres() and PostgreSQL notifications (pgClient.on('notification')) in the ETL and CDC pipeline examples in SKILL.md. \n
  • Boundary markers: No explicit instructions or delimiters are provided to the agent to treat external data as untrusted or to ignore instructions embedded within the data. \n
  • Capability inventory: The skill utilizes clickhouse.query and clickhouse.insert to execute database commands based on ingested data. \n
  • Sanitization: The provided code snippets demonstrate building SQL queries using template literals and string concatenation (VALUES ${values}) without incorporating data sanitization or parameterized queries, which is a common vulnerability surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — clickhouse-io