sink-clickhouse-jsonl
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill validates ClickHouse identifiers (database and table names) using a strict whitelist regular expression (
^[A-Za-z_][A-Za-z0-9_]{0,254}$) to prevent SQL injection in identifier positions. - [SAFE]: Credentials and connection settings are managed through standard environment variables (
CLICKHOUSE_HOST,CLICKHOUSE_USER,CLICKHOUSE_PASSWORD), which is the recommended practice for secure secret handling. - [SAFE]: The skill implements a safety-first approach by defaulting to a dry-run mode, requiring an explicit
--applyflag for actual database write operations. - [SAFE]: Network egress is restricted to the official
*.clickhouse.clouddomain, aligning with the skill's purpose and reducing the risk of unauthorized data exfiltration. - [SAFE]: The implementation uses the official
clickhouse-connectdriver and avoids dangerous operations likeeval(),exec(), or arbitrary SQL execution.
Audit Metadata