db-index-suggest

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by including explicit instructions to avoid connecting to production databases or executing generated SQL.
  • [COMMAND_EXECUTION]: No unauthorized command execution patterns were found. The skill is strictly analytical and restricted by the disable-model-invocation: true flag and a limited toolset (Read, Grep, Glob).
  • [DATA_EXFILTRATION]: No network access tools are requested in the allowed-tools, which prevents data from being sent to external servers.
  • [PROMPT_INJECTION]: Instructions do not contain any attempts to bypass model constraints or hijack the agent's persona. The language used is purely instructional.
  • [DATA_EXPOSURE]: The skill processes user-provided files (SQL logs, schema definitions, and code) for analysis purposes. While it reads local data, it lacks the capabilities (like network access) to exfiltrate this information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:56 PM
Security Audit — agent-trust-hub — db-index-suggest