review-migration
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively provides instructional content for safe database operations and does not exhibit malicious behavior.
- [PROMPT_INJECTION]: No attempts to bypass safety filters or override agent behavior were found. The "HARD-GATE" section contains legitimate, domain-specific safety rules for database migration workflows.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were detected. The skill correctly identifies the need for security checks when migrations involve sensitive data.
- [OBFUSCATION]: No base64, zero-width characters, homoglyphs, or other obfuscation techniques were found in the files.
- [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic execution patterns were identified. The Ruby snippets provided are static code examples used for educational purposes.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to analyze external migration code, it does not demonstrate any exploitable surfaces that could lead to injection. It serves as a defensive framework for reviewing changes.
- [DYNAMIC_CONTEXT_INJECTION]: No dynamic context execution patterns (such as
!commandsyntax) were detected in the skill definitions.
Audit Metadata