oma-db
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user's codebase to generate architectural recommendations, which creates a potential surface for indirect prompt injection attacks.\n- Ingestion points: SKILL.md specifies reading existing database schemas, migration files, query logs, and workload descriptions from the CODEBASE scope.\n- Boundary markers: The skill does not implement explicit delimiters or boundary instructions to prevent the agent from following instructions potentially embedded in the ingested database files.\n- Capability inventory: The agent has the ability to write new migration files, modify schema documentation, and execute local migration or validation tools through the PROCESS scope.\n- Sanitization: There is no evidence of automated sanitization, filtering, or validation of the content read from external project files before it is processed by the model.
Audit Metadata