database-lookup

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from over 80 external database APIs, many of which include user-contributed content such as patent text, clinical notes, and abstracts that could contain malicious instructions.
  • Ingestion points: External API responses documented in the references directory enter the agent context via Bash-driven network requests.
  • Boundary markers: Instructions in SKILL.md mandate labeling raw payloads as untrusted third-party data and returning concise, structured summaries.
  • Capability inventory: The skill employs the Bash tool for network requests and can generate or execute Python scripts for SOAP-based APIs like BRENDA.
  • Sanitization: Step 6 in SKILL.md explicitly forbids following instructions embedded in returned data and requires field validation before using data in subsequent tool calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — database-lookup