drizzle-postgres

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely educational and instructional, providing templates, code snippets, and configuration guides for PostgreSQL and Drizzle ORM.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were detected. The skill correctly demonstrates using environment variables (e.g., process.env.DATABASE_URL) for database connections.
  • [COMMAND_EXECUTION]: The skill mentions standard development commands (e.g., npx drizzle-kit migrate). These are routine for the described technology and are documented as manual developer actions rather than automated agent behaviors.
  • [EXTERNAL_DOWNLOADS]: References to external repositories and documentation (e.g., github.com/drizzle-team/drizzle-orm and postgresql.org) are limited to official, well-known sources for the tools being documented.
  • [SAFE_PRACTICE]: The skill includes explicit warnings against high-risk actions, such as using drizzle-kit push in production environments, and provides guidance on using parameterized queries to prevent SQL injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 08:04 PM
Security Audit — agent-trust-hub — drizzle-postgres