clickhouse-io

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The TypeScript code examples for bulkInsertTrades and the CDC listener demonstrate unsafe interpolation of external data into SQL queries. This pattern presents a vulnerability surface where malicious data from a source database or stream could execute unintended SQL commands.
  • Ingestion points: The trades parameter in bulkInsertTrades and the msg.payload received from the PostgreSQL LISTEN notification in SKILL.md.
  • Boundary markers: No boundary markers or 'ignore' instructions are present to prevent the agent from treating data as instructions.
  • Capability inventory: The skill utilizes the clickhouse library to execute queries and the pg library for database notifications.
  • Sanitization: The examples use template literals (e.g., '${trade.id}') for SQL construction instead of parameterized queries or dedicated escaping functions.
  • [EXTERNAL_DOWNLOADS]: The skill references external Node.js dependencies for database connectivity.
  • Dependencies: clickhouse and pg (PostgreSQL client) are suggested for installation and usage in the provided integration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — clickhouse-io