database-architect

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data, including database schemas and SQL queries, to perform diagnostic and architectural reviews. This creates a surface where a malicious user could attempt to embed instructions within the code being analyzed to manipulate the agent's behavior. \n
  • Ingestion points: User-provided SQL code and schema strings ingested during the diagnosis and review tasks. \n
  • Boundary markers: The SKILL.md instructions include strong grounding requirements, directing the agent to use local reference files as the primary source of truth and to correct users when their requests conflict with these references. \n
  • Capability inventory: The skill's capabilities are restricted to generating advice and SQL snippets; it does not possess tools for network access, arbitrary shell command execution, or persistent file system modifications. \n
  • Sanitization: The skill implements a validation layer that identifies and warns against SQL injection patterns, such as string interpolation in raw queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 PM
Security Audit — agent-trust-hub — database-architect