clickhouse-io
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The TypeScript code examples for
bulkInsertTradesand the CDC listener demonstrate unsafe interpolation of external data into SQL queries. This pattern presents a vulnerability surface where malicious data from a source database or stream could execute unintended SQL commands. - Ingestion points: The
tradesparameter inbulkInsertTradesand themsg.payloadreceived from the PostgreSQLLISTENnotification inSKILL.md. - Boundary markers: No boundary markers or 'ignore' instructions are present to prevent the agent from treating data as instructions.
- Capability inventory: The skill utilizes the
clickhouselibrary to execute queries and thepglibrary for database notifications. - Sanitization: The examples use template literals (e.g.,
'${trade.id}') for SQL construction instead of parameterized queries or dedicated escaping functions. - [EXTERNAL_DOWNLOADS]: The skill references external Node.js dependencies for database connectivity.
- Dependencies:
clickhouseandpg(PostgreSQL client) are suggested for installation and usage in the provided integration patterns.
Audit Metadata