skills/loadchange/aepipe/query-aepipe/Gen Agent Trust Hub

query-aepipe

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md provide clear operational guidance for the agent. No attempts to bypass safety filters or override system instructions were identified.\n- [DATA_EXFILTRATION]: Network activity is confined to the user-defined API endpoint. The skill does not attempt to access sensitive system files like SSH keys or AWS credentials for transmission to unauthorized locations.\n- [COMMAND_EXECUTION]: The skill uses local Python scripts for its core logic. A best-practice violation was noted in query_processor.py where SQL schema is dynamically generated from input data keys; however, this is restricted to the local SQLite export feature and does not allow for arbitrary system command execution.\n- [CREDENTIALS_UNSAFE]: The setup_config.py script securely handles the administrative API token by storing it in a local JSON file with restricted filesystem permissions (0o600).\n- [EXTERNAL_DOWNLOADS]: No external code or package downloads are performed at runtime. The skill relies exclusively on the Python standard library.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 03:31 AM
Security Audit — agent-trust-hub — query-aepipe