go-data-persistence

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements industry best practices for database security, specifically emphasizing the prevention of SQL injection through the mandatory use of bind parameters ($1, :name) and prohibiting string concatenation in queries.
  • [SAFE]: Secret management follows best practices by retrieving sensitive information like the database connection string from environment variables (os.Getenv("DATABASE_URL")) rather than hardcoding credentials.
  • [SAFE]: Database migration patterns include safety measures such as idempotent SQL (IF NOT EXISTS), transaction-wrapped DDL for consistency, and concurrent index creation to avoid table locking on large datasets.
  • [SAFE]: The skill provides robust connection pooling configurations and monitoring patterns, ensuring resource stability and preventing common pitfalls like opening a new connection per request.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface for SQL queries and migrations but implements strong mitigations.
  • Ingestion points: SQL templates and request data in repository methods (SKILL.md), migration files (references/migrations.md).
  • Boundary markers: Type-safe interfaces (DBTX) and parameterized query placeholders ($1, :name).
  • Capability inventory: Database operations via database/sql and pgx across all files; filesystem read in migrations.md.
  • Sanitization: Instructions explicitly mandate bind parameters and allowlists for dynamic identifiers, preventing schema confusion and injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — go-data-persistence