sqlalchemy

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides implementation patterns for data ingestion and database persistence, creating an indirect prompt injection surface.
  • Ingestion points: The UserCRUD class in SKILL.md defines methods such as create, update, and get_by_email that accept and process external input data.
  • Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to disregard potential instructions embedded within the data retrieved from or sent to the database.
  • Capability inventory: The skill provides full database lifecycle management capabilities, including reading, writing, updating, and deleting records via AsyncSession operations in SKILL.md.
  • Sanitization: The implementation examples do not demonstrate input validation, escaping, or sanitization protocols for external data before it is interpolated into database queries or persisted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 07:53 PM
Security Audit — agent-trust-hub — sqlalchemy