drizzle-sqlite-scaffold

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides boilerplate templates for Drizzle ORM and SQLite. It implements standard security and performance practices, such as enabling foreign key enforcement and Write-Ahead Logging (WAL) mode via SQLite pragmas.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to install standard, well-known Node.js packages from the official NPM registry, including drizzle-orm, drizzle-kit, and driver-specific clients like better-sqlite3 or @libsql/client.
  • [COMMAND_EXECUTION]: The skill uses standard CLI commands (npm install, npx drizzle-kit) to manage project dependencies and database migrations. These are executed within the context of project initialization and development workflows.
  • [SAFE]: Database credentials are not hardcoded; templates correctly reference environment variables (e.g., process.env.DATABASE_URL) and the skill explicitly includes a .gitignore template to prevent committing local database files or sensitive environment configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — drizzle-sqlite-scaffold