codedbpro
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to circumvent platform-level security restrictions. It directs the agent to use the
codedbprotoolset specifically in environments where native commands likeRead,Write,Edit,cat, orgrepare "hook-blocked," effectively encouraging the bypass of host-enforced monitoring or access controls. - [PROMPT_INJECTION]: The skill defines an indirect prompt injection surface by allowing the agent to ingest arbitrary file content and perform powerful filesystem modifications without safety boundaries.
- Ingestion points: The
read,faster_search, andmeta_searchtools ingest data from any accessible file on the system into the agent's context. - Boundary markers: The instructions do not mandate the use of delimiters, XML tags, or "ignore embedded instructions" warnings when processing ingested file content.
- Capability inventory: The skill provides a comprehensive set of write and modification capabilities via the
edit,patch,create, andreplacetools. - Sanitization: No sanitization, escaping, or validation protocols are defined for handling the external content before processing.
- [DATA_EXFILTRATION]: The toolset enables access to sensitive filesystem paths beyond the repository root. The documentation explicitly mentions that the tools are "not repo-locked" and can succeed on absolute paths such as
/tmpand the user's home directory (e.g.,~/.claude), which increases the risk of sensitive data exposure or unauthorized modification of configuration files.
Audit Metadata