duckdb-sql

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides documentation for executing SQL queries via shell commands using Python's command-line interface.
  • [PROMPT_INJECTION]: The skill processes external data files which constitutes an indirect prompt injection surface.
  • Ingestion points: Ingests data from local CSV, Parquet, and JSON files via DuckDB SQL (SKILL.md).
  • Boundary markers: No explicit instruction-ignoring delimiters are defined for the data content.
  • Capability inventory: Executes SQL queries and file export operations using the duckdb Python package.
  • Sanitization: No data sanitization or validation logic is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 02:07 AM