sql-best-practice
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of documentation and configuration files. There are no executable scripts, shell commands, or binary files included in the skill package.
- [SAFE]: The external links provided in
references/best-practices.mdare to well-known, official documentation sites for SQL dialects (PostgreSQL, MySQL, Oracle, Microsoft SQL Server) and a recognized community style guide. These are informational resources and do not represent a security risk. - [DATA_EXFILTRATION]: There are no network operations, credential requirements, or file access patterns detected. The skill operates as a static reference for the AI agent.
- [PROMPT_INJECTION]: The instructions are clearly defined as a set of best practices for SQL review. There are no patterns suggesting overrides of safety filters or instructions to ignore previous rules.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided SQL code (untrusted data), its capabilities are limited to providing textual review and recommendations. It does not possess capabilities for file writing, network transmission, or code execution that could be exploited by an indirect injection attack.
Audit Metadata