database-design
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's documentation, covering database selection, indexing, and migration strategies, contains only legitimate technical guidance without malicious instructions or prompt injection attempts.- [SAFE]: The
scripts/schema_validator.pyscript is a standard local utility. It uses built-in Python libraries to perform structural checks on Prisma and Drizzle schema files. It does not exhibit risky behaviors such as network connectivity, sensitive file access, or dynamic code execution.- [INDIRECT_PROMPT_INJECTION]: The skill includes a schema validator that processes external project files, which constitutes a potential ingestion surface for untrusted data. 1. Ingestion points:scripts/schema_validator.pyreads content from file paths identified viaglob. 2. Boundary markers: Absent. The script prints extracted identifiers and error messages directly. 3. Capability inventory: The skill environment allowsRead,Write,Edit,Glob, andGrepoperations. 4. Sanitization: Absent. Substrings from input files are interpolated into printed issue messages. This surface is assessed as safe given the tool's intended use-case for static code analysis.
Audit Metadata