database
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions in
references/query.mddirect the agent to automatically search for and read database credentials from sensitive locations, including.envfiles and workspace configuration folders. - Evidence:
references/query.mdspecifies discovery paths likeworkspace/.env/databases/anddatabases/subfolders within service directories to retrieve host, user, and password information. - [DYNAMIC_EXECUTION]: The
references/tuning.mdfile outlines a "Semantic Optimization Loop" where the agent is instructed to propose configuration candidates and execute controlled benchmarks or load tests iteratively. - Evidence: The skill describes an automated process for tuning parameters (e.g., connection pools, cache TTLs) using a closed-loop objective evaluation that involves running live load tests to measure latency and throughput.
- [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting and processing data from external databases, which constitutes a large attack surface for indirect prompt injection from untrusted data sources.
- Ingestion points: The
querymode reads arbitrary rows and schema information from configured databases (references/query.md). - Boundary markers: While the skill enforces read-only session states and tabular output, it lacks explicit boundary markers to prevent the agent from interpreting instructions embedded within the database records it retrieves.
- Capability inventory: The agent has access to powerful tools including
bash,run_command,write_to_file, andreplace_file_content(SKILL.md). - Sanitization: The skill performs sanitization on error outputs to prevent credential leakage but does not sanitize the content of the database rows themselves before they enter the agent's context.
- [COMMAND_EXECUTION]: The skill makes extensive use of
bashandrun_commandto interface with various database engines and system utilities, creating a risk of command injection if user-supplied query parameters or database metadata are not properly handled. - Evidence: Both
SKILL.mdandagents/openai.yamllistbashandrun_commandas required tools for diagnosing performance issues, running benchmarks, and executing database CLI tools.
Audit Metadata