db
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an AI-assisted query generation workflow where user descriptions are used to generate SQL commands. This represents an attack surface where a malicious description could potentially influence the AI to generate destructive or unauthorized queries.
- Evidence: The skill mitigates this by providing a 'Safe Query Review' pattern, instructing users to review generated code (
echo "$QUERY") before execution. - [DYNAMIC_EXECUTION]: The skill documents the generation of SQL code via the
geminiCLI and its subsequent execution through database clients. While this involves dynamic code generation, it is the primary purpose of the tool and is coupled with clear safety warnings. - [COMMAND_EXECUTION]: The skill facilitates the execution of standard database CLI tools (
psql,mysql,sqlite3) to interact with local and remote data. It correctly advises storing sensitive connection strings in environment variables to prevent accidental exposure.
Audit Metadata