database-design
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes a validation script (scripts/schema_validator.py) that reads and processes untrusted database schema files from the project directory, creating a surface for indirect prompt injection.
- Ingestion points: The script reads content from files matching
**/prisma/schema.prismaand**/drizzle/*.tsusing the Path.read_text method. - Boundary markers: The script output does not implement delimiters or specific instructions to prevent the agent from interpreting malicious instructions that could be embedded in schema model names or comments.
- Capability inventory: The skill is configured with Read, Write, Edit, Glob, and Grep tools, which could be misused if the agent's behavior is influenced by the ingested schema data.
- Sanitization: The script performs regex-based extraction but does not sanitize or escape the content of the schema files before presenting the analysis results to the agent.
Audit Metadata