skills/ericrisco/rsc-harness/duckdb/Gen Agent Trust Hub

duckdb

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the installation of the DuckDB CLI using a shell script from the official domain (install.duckdb.org). This is a well-known and accepted installation method for this technology.
  • [COMMAND_EXECUTION]: The provided 'verify.sh' utility executes local shell and Python commands to perform smoke tests on sample data. It utilizes temporary directories and does not require elevated privileges.
  • [PROMPT_INJECTION]: The skill identifies SQL injection risks and instructs users to use parameterized queries rather than string concatenation. Additionally, it identifies an indirect prompt injection surface because the skill processes external data files.
  • Ingestion points: The skill reads external CSV, Parquet, and JSON files via 'read_csv_auto' and 'read_parquet' in 'SKILL.md'.
  • Boundary markers: None are explicitly defined in the code examples to delimit untrusted data.
  • Capability inventory: The skill can execute SQL queries and write files to disk via the 'COPY TO' command.
  • Sanitization: The 'references/python-and-interop.md' file recommends using parameterized queries to sanitize input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — duckdb