duckdb-sql
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides documentation for executing SQL queries via shell commands using Python's command-line interface.
- [PROMPT_INJECTION]: The skill processes external data files which constitutes an indirect prompt injection surface.
- Ingestion points: Ingests data from local CSV, Parquet, and JSON files via DuckDB SQL (SKILL.md).
- Boundary markers: No explicit instruction-ignoring delimiters are defined for the data content.
- Capability inventory: Executes SQL queries and file export operations using the
duckdbPython package. - Sanitization: No data sanitization or validation logic is provided.
Audit Metadata