astro-database

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill emphasizes the use of parameterized queries and ORM-based query builders to prevent SQL injection vulnerabilities when handling user input.
  • [SAFE]: Instructions explicitly mandate storing connection strings and sensitive credentials in server-side environment variables, specifically warning against using PUBLIC_ prefixes that would expose them to the client.
  • [SAFE]: Database access logic is restricted to server-only runtimes (actions, endpoints, and middleware), ensuring that database drivers and connection logic are never shipped to the client browser.
  • [SAFE]: The skill references well-known and established ecosystem tools such as Drizzle ORM, pg, and better-sqlite3, which are standard for the described use cases.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 04:10 PM
Security Audit — agent-trust-hub — astro-database