planetscale-readonly-inventory

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is authored by PlanetScale and restricts its operations to read-only inventory tasks using official vendor tools and APIs. Actions that modify the state of the database or infrastructure are explicitly disallowed.
  • [SAFE]: The instructions include specific safeguards, such as prohibiting the emission of new credentials and advising against the termination of connections or queries without explicit approval.
  • [SAFE]: External references target official PlanetScale documentation and OpenAPI specifications, which are legitimate sources for grounding the agent's actions within the vendor's ecosystem.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process data from external sources including repository files (migrations, configuration) and API responses (schema recommendations, query insights). This ingestion is central to the skill's purpose of performing a comprehensive inventory.
  • Ingestion points: Reads from repository files, CLI command outputs, and PlanetScale API responses.
  • Boundary markers: The instructions do not define specific delimiters for separating untrusted external data from the system prompt.
  • Capability inventory: The agent is authorized to use the pscale CLI and perform network requests to the PlanetScale API.
  • Sanitization: No specific sanitization or filtering logic is provided for the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 06:27 AM
Security Audit — agent-trust-hub — planetscale-readonly-inventory