database-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment enumeration by running ls commands on hidden directories in the user's home folder (e.g., ~/.claude/skills/, ~/.agent/skills/) to identify other installed companion skills. This maps out the user's environment without explicit user initiation.
  • [REMOTE_CODE_EXECUTION]: The skill recommends the installation of external components via npx skills add AbsolutelySkilled/AbsolutelySkilled. This process involves fetching and executing code from a remote source that is not part of a verified ecosystem, which could lead to the execution of unverified scripts.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted user-provided data such as SQL schemas and query plans.
  • Ingestion points: User-provided database schemas and query plans in the conversation context (specifically within the SQL design and optimization triggers).
  • Boundary markers: Absent. No delimiters or specific instructions to ignore embedded commands are provided to the agent within the SKILL.md instructions.
  • Capability inventory: Shell access (via the ls command), SQL generation, and local environment inspection.
  • Sanitization: Absent. The skill does not specify validation, escaping, or filtering of the external SQL or EXPLAIN plan content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — database-engineering