database

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions in references/query.md direct the agent to automatically search for and read database credentials from sensitive locations, including .env files and workspace configuration folders.
  • Evidence: references/query.md specifies discovery paths like workspace/.env/databases/ and databases/ subfolders within service directories to retrieve host, user, and password information.
  • [DYNAMIC_EXECUTION]: The references/tuning.md file outlines a "Semantic Optimization Loop" where the agent is instructed to propose configuration candidates and execute controlled benchmarks or load tests iteratively.
  • Evidence: The skill describes an automated process for tuning parameters (e.g., connection pools, cache TTLs) using a closed-loop objective evaluation that involves running live load tests to measure latency and throughput.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting and processing data from external databases, which constitutes a large attack surface for indirect prompt injection from untrusted data sources.
  • Ingestion points: The query mode reads arbitrary rows and schema information from configured databases (references/query.md).
  • Boundary markers: While the skill enforces read-only session states and tabular output, it lacks explicit boundary markers to prevent the agent from interpreting instructions embedded within the database records it retrieves.
  • Capability inventory: The agent has access to powerful tools including bash, run_command, write_to_file, and replace_file_content (SKILL.md).
  • Sanitization: The skill performs sanitization on error outputs to prevent credential leakage but does not sanitize the content of the database rows themselves before they enter the agent's context.
  • [COMMAND_EXECUTION]: The skill makes extensive use of bash and run_command to interface with various database engines and system utilities, creating a risk of command injection if user-supplied query parameters or database metadata are not properly handled.
  • Evidence: Both SKILL.md and agents/openai.yaml list bash and run_command as required tools for diagnosing performance issues, running benchmarks, and executing database CLI tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — database