clickhouse

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as an expert knowledge base for ClickHouse, containing 28 rules and 15 reference files. The instructions focus on improving performance, storage efficiency, and operational stability.
  • [SAFE]: Hardcoded credentials found in references/backup-restore.md and references/integrations.md (e.g., AKIAIOSFODNN7EXAMPLE, password123) are clearly identified as placeholders. The skill includes a dedicated 'Security Considerations' section in SKILL.md advising users to never use these in production and recommending the use of environment variables, secret managers, or Kubernetes secrets.
  • [SAFE]: External downloads and dependencies mentioned (e.g., clickhouse-backup, clickhouse-sqlalchemy) are standard tools within the ClickHouse ecosystem. Links point to official documentation (clickhouse.com) and established community repositories on GitHub.
  • [SAFE]: The skill uses natural instructional language to guide the agent's behavior. The use of 'IMPORTANT' and 'MUST' headers is consistent with technical documentation and does not constitute a malicious prompt injection intended to bypass safety filters.
  • [SAFE]: There is no evidence of obfuscation (Base64, zero-width characters), persistence mechanisms, or unauthorized network exfiltration. All documented commands and SQL patterns are relevant to the stated purpose of ClickHouse administration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:36 AM
Security Audit — agent-trust-hub — clickhouse