database-optimizer
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides various SQL templates for database administration, such as modifying global server configurations (ALTER SYSTEM SET, SET GLOBAL), installing extensions, and managing schema objects. These operations require elevated database privileges.\n- [DATA_EXFILTRATION]: The skill facilitates the inspection of internal database activity logs (pg_stat_activity, performance_schema) and query statistics. These views may expose sensitive data, application logic, or PII contained within query strings.\n- [PROMPT_INJECTION]: The skill processes untrusted database output. Evidence chain: 1. Ingestion points: EXPLAIN output and statistics logs (SKILL.md, references/monitoring-analysis.md). 2. Boundary markers: Logic is segmented into 'Analyze' and 'Identify' workflow steps. 3. Capability inventory: Generation of administrative SQL queries. 4. Sanitization: No explicit validation or filtering of database output before interpolation.
Audit Metadata