sota-databases

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of high-quality engineering guidelines and best practices for database management. It does not perform any automated code execution, network exfiltration, or credential harvesting.
  • [DATA_EXPOSURE]: The instructions explicitly emphasize data security, providing detailed rules for implementing Row-Level Security (RLS), least-privilege access, and encryption at rest and in transit. It specifically warns against storing secrets in plain text or hardcoding credentials.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety guidelines were found. The 'Top 10 non-negotiables' and 'AUDIT mode' instructions reinforce safe and predictable agent behavior.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It mentions standard database tools (e.g., pgBackRest, Flyway, Alembic) in a purely advisory capacity for the user's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided data structures (schemas, queries, migrations). This ingestion creates a theoretical surface for indirect prompt injection; however, the skill's internal logic is heavily focused on safety auditing and security constraints, which significantly mitigates the risk of an agent following instructions embedded within the analyzed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:16 PM
Security Audit — agent-trust-hub — sota-databases