migration-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests user-provided database migration scripts and plans for analysis. This surface is inherent to its function as a code review advisory tool. Evidence Chain: 1. Ingestion points: User requests and provided SQL/Python migration scripts. 2. Boundary markers: Instructions in SKILL.md explicitly mandate grounding in internal reference files and correcting user errors. 3. Capability inventory: No external tool access or shell command execution is permitted. 4. Sanitization: No explicit content filtering is present.
- [SAFE]: No malicious patterns such as credential exfiltration, remote code execution, or obfuscation were found. The skill serves a purely educational and advisory purpose, promoting safe database administration practices. The provided SQL and Python code snippets are illustrative examples of defensive coding and do not perform any unauthorized operations.
Audit Metadata