sqlite
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The installation script
scripts/install.shutilizessudoto execute package management commands such asapt,dnf,pacman, andapkfor installing thesqlite3utility on Linux systems. - [COMMAND_EXECUTION]: The script
scripts/install.ps1modifies the systemPATHenvironment variable to include the installation directory for SQLite tools, ensuring they are available for command-line execution. - [EXTERNAL_DOWNLOADS]: During the installation process,
scripts/install.ps1downloads a ZIP archive containing SQLite binaries from the officialsqlite.orgwebsite. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied database files and SQL queries, which creates a surface for indirect prompt injection if the inputs contain adversarial instructions.
- Ingestion points: Database files provided via the
--dbflag and SQL content provided via--sqlor--sql-fileinscripts/sqlite_safe_query.shandscripts/sqlite_migration_validate.sh. - Boundary markers: The safe query wrapper uses the
-readonlyflag and.bail onsettings to restrict operations; however, there are no specific prompt delimiters or instructions to ignore embedded content. - Capability inventory: The skill can read, write, and backup database files, and it can invoke the
sqlite3CLI for complex operations including replica synchronization via SSH. - Sanitization: The
scripts/sqlite_safe_query.shscript rejects SQL input that begins with SQLite dot-commands to prevent accidental execution of shell or meta-commands.
Audit Metadata