skills/klh/speedy-claude/sqlite/Gen Agent Trust Hub

sqlite

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The installation script scripts/install.sh utilizes sudo to execute package management commands such as apt, dnf, pacman, and apk for installing the sqlite3 utility on Linux systems.
  • [COMMAND_EXECUTION]: The script scripts/install.ps1 modifies the system PATH environment variable to include the installation directory for SQLite tools, ensuring they are available for command-line execution.
  • [EXTERNAL_DOWNLOADS]: During the installation process, scripts/install.ps1 downloads a ZIP archive containing SQLite binaries from the official sqlite.org website.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied database files and SQL queries, which creates a surface for indirect prompt injection if the inputs contain adversarial instructions.
  • Ingestion points: Database files provided via the --db flag and SQL content provided via --sql or --sql-file in scripts/sqlite_safe_query.sh and scripts/sqlite_migration_validate.sh.
  • Boundary markers: The safe query wrapper uses the -readonly flag and .bail on settings to restrict operations; however, there are no specific prompt delimiters or instructions to ignore embedded content.
  • Capability inventory: The skill can read, write, and backup database files, and it can invoke the sqlite3 CLI for complex operations including replica synchronization via SSH.
  • Sanitization: The scripts/sqlite_safe_query.sh script rejects SQL input that begins with SQLite dot-commands to prevent accidental execution of shell or meta-commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — sqlite