install-duckdb

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to install the DuckDB CLI using a remote script piped to a shell: curl -fsSL https://install.duckdb.org | sh. This is the project's official installation method and targets the vendor's own infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the latest stable version number from https://duckdb.org/data/latest_stable_version.txt to determine if an upgrade is required.
  • [COMMAND_EXECUTION]: The skill executes shell commands to interact with the DuckDB CLI, Homebrew (brew), and Windows Package Manager (winget) for software installation and updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied arguments to build SQL commands for the DuckDB CLI.
  • Ingestion points: User-provided arguments $@ are parsed to extract extension names and repository locations.
  • Boundary markers: None identified. The skill relies on the AI agent to correctly format the SQL INSTALL and UPDATE statements.
  • Capability inventory: The skill uses the Bash tool to execute duckdb CLI commands and perform network requests via curl.
  • Sanitization: There is no explicit sanitization step described for the extension names before they are interpolated into the SQL command strings (e.g., INSTALL <name>). Safety relies on the agent's internal logic and the DuckDB CLI's own command parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:19 PM