planetscale-safe-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the 'pscale' CLI and 'pscale api' to perform inventory and state checks. This is the official vendor tool and is consistent with the skill's purpose.
- [EXTERNAL_DOWNLOADS]: The skill references official PlanetScale documentation (e.g., planetscale.com/docs/llms.txt) and the OpenAPI specification to ground its operations in factual data. These sources belong to the vendor and are considered safe.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from the user's repository code, application logs, and database telemetry.
- Ingestion points: Processes repository files, application frameworks, and database query telemetry (Phase 3 and Phase 7).
- Boundary markers: The skill uses a structured progress checklist and specific report templates (Phase 10) to organize output.
- Capability inventory: The orchestrator can invoke the PlanetScale CLI, call MCP servers, and execute sub-skills that may write changes (if approved).
- Sanitization: The instructions emphasize following official templates and using specific ID schemes, which limits the influence of external data on the final report structure.
Audit Metadata