helix-query-go
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains legitimate instructions and examples for software development using the HelixDB Go SDK. All external references point to the author's own repositories or common documentation sites.- [INDIRECT_PROMPT_INJECTION]: The instructions include a defensive measure by directing the agent to treat results from the 'helix-mcp' tool as untrusted data, effectively reducing the risk of indirect prompt injection from external database insights.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses safe, descriptive placeholders (e.g., 'hx_secret', 'https://helix.example.com') in code examples instead of hardcoding any real sensitive information.- [REMOTE_CODE_EXECUTION]: There are no patterns of downloading and executing arbitrary scripts or binaries. The Go module dependency belongs to the established vendor of the skill.
Audit Metadata