skills/deligoez/skills/codedbpro/Gen Agent Trust Hub

codedbpro

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to circumvent platform-level security restrictions. It directs the agent to use the codedbpro toolset specifically in environments where native commands like Read, Write, Edit, cat, or grep are "hook-blocked," effectively encouraging the bypass of host-enforced monitoring or access controls.
  • [PROMPT_INJECTION]: The skill defines an indirect prompt injection surface by allowing the agent to ingest arbitrary file content and perform powerful filesystem modifications without safety boundaries.
  • Ingestion points: The read, faster_search, and meta_search tools ingest data from any accessible file on the system into the agent's context.
  • Boundary markers: The instructions do not mandate the use of delimiters, XML tags, or "ignore embedded instructions" warnings when processing ingested file content.
  • Capability inventory: The skill provides a comprehensive set of write and modification capabilities via the edit, patch, create, and replace tools.
  • Sanitization: No sanitization, escaping, or validation protocols are defined for handling the external content before processing.
  • [DATA_EXFILTRATION]: The toolset enables access to sensitive filesystem paths beyond the repository root. The documentation explicitly mentions that the tools are "not repo-locked" and can succeed on absolute paths such as /tmp and the user's home directory (e.g., ~/.claude), which increases the risk of sensitive data exposure or unauthorized modification of configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:34 AM
Security Audit — agent-trust-hub — codedbpro