surrealdb-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides extensive documentation on security best practices, including row-level security (RLS), parameterized queries to prevent injection, and proper password hashing using Argon2. It also lists known security advisories (GHSAs) for SurrealDB to ensure developers are aware of potential risks in specific versions.
- [CREDENTIALS_UNSAFE]: The skill contains hardcoded default credentials (
root:root) within a Python test fixture intended forlocalhostdevelopment. However, the skill body explicitly warns against hardcoding credentials in production and provides instructions for secure secret management using environment variables, which is a standard and acceptable practice for educational content. - [INDIRECT_PROMPT_INJECTION]: The skill addresses this risk by providing robust patterns for data validation (using
ASSERTandTYPEmodifiers) and access control, effectively teaching the AI agent and the user how to build secure interfaces that resist untrusted input.
Audit Metadata