text-to-sql
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes natural language input from users to generate SQL queries, which constitutes a potential injection surface. However, the skill implements robust safety guardrails to mitigate this risk.
- Ingestion points: User-provided natural language queries are processed as described in the
SKILL.mdusage section. - Boundary markers: The 'Iron Laws' section explicitly instructs the agent to validate all identifiers against the schema and explain query logic before execution to ensure user oversight.
- Capability inventory: The skill frontmatter lists access to
Read,Write,Grep, andGlobtools, but the included scripts (main.cjs,pre-execute.cjs,post-execute.cjs) do not perform any dangerous file or network operations. - Sanitization: The skill mandates the use of parameterized queries to prevent SQL injection and enforces a mandatory
LIMITclause on SELECT queries to prevent resource exhaustion. - [SAFE]: The skill references established industry resources and tools for testing and development.
- Documentation references the official Anthropic cookbook for text-to-SQL implementation patterns.
- The evaluation section suggests using
promptfoo, a well-known open-source tool for testing LLM outputs, vianpx.
Audit Metadata