sota-databases
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of high-quality engineering guidelines and best practices for database management. It does not perform any automated code execution, network exfiltration, or credential harvesting.
- [DATA_EXPOSURE]: The instructions explicitly emphasize data security, providing detailed rules for implementing Row-Level Security (RLS), least-privilege access, and encryption at rest and in transit. It specifically warns against storing secrets in plain text or hardcoding credentials.
- [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety guidelines were found. The 'Top 10 non-negotiables' and 'AUDIT mode' instructions reinforce safe and predictable agent behavior.
- [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It mentions standard database tools (e.g., pgBackRest, Flyway, Alembic) in a purely advisory capacity for the user's environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided data structures (schemas, queries, migrations). This ingestion creates a theoretical surface for indirect prompt injection; however, the skill's internal logic is heavily focused on safety auditing and security constraints, which significantly mitigates the risk of an agent following instructions embedded within the analyzed data.
Audit Metadata