planetscale-mcp-agent-operating-model

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing external data such as database insights and repository source code. It includes robust safeguards such as tiered authorization (Tier 1 for proposals, Tier 2 for execution) and mandatory human-in-the-loop approvals to mitigate potential injection risks.\n
  • Ingestion points: Database telemetry, schema recommendations, and repository source code (SKILL.md).\n
  • Boundary markers: Defined in project-specific AGENTS.md and through explicit tiered authorization modes (SKILL.md).\n
  • Capability inventory: Database query execution via MCP, PR/branch creation, and CLI automation (SKILL.md).\n
  • Sanitization: Human approval gates for all mutations and the use of read-only replicas by default (SKILL.md).\n- [EXTERNAL_DOWNLOADS]: The skill references the official PlanetScale CLI GitHub repository for technical guidance.\n- [COMMAND_EXECUTION]: The skill mentions using the pscale CLI tool for automation, emphasizing safe usage patterns and machine-readable output formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:04 AM
Security Audit — agent-trust-hub — planetscale-mcp-agent-operating-model