go-data-persistence
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements industry best practices for database security, specifically emphasizing the prevention of SQL injection through the mandatory use of bind parameters ($1, :name) and prohibiting string concatenation in queries.
- [SAFE]: Secret management follows best practices by retrieving sensitive information like the database connection string from environment variables (os.Getenv("DATABASE_URL")) rather than hardcoding credentials.
- [SAFE]: Database migration patterns include safety measures such as idempotent SQL (IF NOT EXISTS), transaction-wrapped DDL for consistency, and concurrent index creation to avoid table locking on large datasets.
- [SAFE]: The skill provides robust connection pooling configurations and monitoring patterns, ensuring resource stability and preventing common pitfalls like opening a new connection per request.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface for SQL queries and migrations but implements strong mitigations.
- Ingestion points: SQL templates and request data in repository methods (SKILL.md), migration files (references/migrations.md).
- Boundary markers: Type-safe interfaces (DBTX) and parameterized query placeholders ($1, :name).
- Capability inventory: Database operations via database/sql and pgx across all files; filesystem read in migrations.md.
- Sanitization: Instructions explicitly mandate bind parameters and allowlists for dynamic identifiers, preventing schema confusion and injection.
Audit Metadata