graph-database-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded default credentials 'root/root' for a local SurrealDB instance are provided in test fixtures within SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with and processes external graph data, which presents a surface for indirect prompt injection if the retrieved content contains malicious instructions.
  • Ingestion points: SurrealQL query results are processed and returned to the agent context as shown in SKILL.md and src/graph/queries.py examples.
  • Boundary markers: None explicitly defined in the provided code snippets for agent prompt interpolation.
  • Capability inventory: The skill utilizes the surrealdb package for network communication with database servers and encourages the use of pytest for local command execution.
  • Sanitization: The skill correctly prioritizes parameterized queries as a critical mitigation against injection into the database layers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — graph-database-expert