text-to-sql

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes natural language input from users to generate SQL queries, which constitutes a potential injection surface. However, the skill implements robust safety guardrails to mitigate this risk.
  • Ingestion points: User-provided natural language queries are processed as described in the SKILL.md usage section.
  • Boundary markers: The 'Iron Laws' section explicitly instructs the agent to validate all identifiers against the schema and explain query logic before execution to ensure user oversight.
  • Capability inventory: The skill frontmatter lists access to Read, Write, Grep, and Glob tools, but the included scripts (main.cjs, pre-execute.cjs, post-execute.cjs) do not perform any dangerous file or network operations.
  • Sanitization: The skill mandates the use of parameterized queries to prevent SQL injection and enforces a mandatory LIMIT clause on SELECT queries to prevent resource exhaustion.
  • [SAFE]: The skill references established industry resources and tools for testing and development.
  • Documentation references the official Anthropic cookbook for text-to-SQL implementation patterns.
  • The evaluation section suggests using promptfoo, a well-known open-source tool for testing LLM outputs, via npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:42 PM
Security Audit — agent-trust-hub — text-to-sql