database-engineering
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment enumeration by running
lscommands on hidden directories in the user's home folder (e.g.,~/.claude/skills/,~/.agent/skills/) to identify other installed companion skills. This maps out the user's environment without explicit user initiation. - [REMOTE_CODE_EXECUTION]: The skill recommends the installation of external components via
npx skills add AbsolutelySkilled/AbsolutelySkilled. This process involves fetching and executing code from a remote source that is not part of a verified ecosystem, which could lead to the execution of unverified scripts. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted user-provided data such as SQL schemas and query plans.
- Ingestion points: User-provided database schemas and query plans in the conversation context (specifically within the SQL design and optimization triggers).
- Boundary markers: Absent. No delimiters or specific instructions to ignore embedded commands are provided to the agent within the SKILL.md instructions.
- Capability inventory: Shell access (via the
lscommand), SQL generation, and local environment inspection. - Sanitization: Absent. The skill does not specify validation, escaping, or filtering of the external SQL or EXPLAIN plan content before processing.
Audit Metadata