clickhouse-io
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines data pipeline patterns that ingest untrusted information from external systems.\n
- Ingestion points: External data enters via the
etlPipelinefunction and the PostgreSQL notification listener in the CDC pattern (SKILL.md).\n - Boundary markers: The skill does not employ delimiters or guardrail instructions to isolate external data from the execution logic.\n
- Capability inventory: The skill possesses database execution capabilities through the
clickhouseandpgmodules.\n - Sanitization: The provided examples use direct template literal interpolation for SQL values without demonstrating sanitization or escaping protocols.
Audit Metadata