clickhouse-io

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its recommended data ingestion patterns. It provides examples that process external data from sources like PostgreSQL notifications and ETL pipelines without implementing boundary markers or sanitization.\n
  • Ingestion points: Data is ingested via the trades parameter in the bulkInsertTrades function and the PostgreSQL notification event handler in SKILL.md.\n
  • Boundary markers: No delimiters or instructions are provided to the agent to treat the ingested data as untrusted or to ignore potentially malicious embedded content.\n
  • Capability inventory: The skill demonstrates the use of the clickhouse.query() method to execute SQL commands.\n
  • Sanitization: The code patterns utilize direct string interpolation (e.g., ${trade.id}) instead of parameterized queries or escaping mechanisms, creating a vulnerability surface.\n- [COMMAND_EXECUTION]: The provided TypeScript examples demonstrate the construction of SQL statements using string concatenation. This approach is a known vector for SQL injection if the source data is controlled by a malicious actor.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — clickhouse-io