dolt-mcp-vcs

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to perform database diagnostics and version-control tasks. This includes the use of curl for network-based verification and data retrieval from external APIs.
  • [CREDENTIALS_UNSAFE]: The skill implements a credential resolution mechanism (creds-ref) capable of retrieving secrets from environment variables and local secret management tools such as sops and pass. While the implementation includes instructions against logging resolved secrets and employs fail-closed logic, the ability to programmatically access local secret stores represents an expanded attack surface for potential exfiltration if the agent is compromised.
  • [EXTERNAL_DOWNLOADS]: The agent is instructed to fetch live documentation and status updates from GitHub (github.com/gastownhall/beads) and the DoltHub API. These sources are considered well-known and professional services in the context of the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Dolt databases and remote documentation files, creating an ingestion point for potentially untrusted content. While the skill provides validation logic for SQL identifiers to prevent traditional SQL injection, it lacks explicit prompt boundary markers to protect the LLM from adversarial instructions embedded in the ingested natural language data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 09:58 AM
Security Audit — agent-trust-hub — dolt-mcp-vcs