oma-db

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user's codebase to generate architectural recommendations, which creates a potential surface for indirect prompt injection attacks.\n- Ingestion points: SKILL.md specifies reading existing database schemas, migration files, query logs, and workload descriptions from the CODEBASE scope.\n- Boundary markers: The skill does not implement explicit delimiters or boundary instructions to prevent the agent from following instructions potentially embedded in the ingested database files.\n- Capability inventory: The agent has the ability to write new migration files, modify schema documentation, and execute local migration or validation tools through the PROCESS scope.\n- Sanitization: There is no evidence of automated sanitization, filtering, or validation of the content read from external project files before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-db