migrate-validate
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation includes a CLI command 'npx @claude-flow/cli@latest' which downloads and executes code from the npm registry. This package is not hosted by a recognized trusted organization or well-known service.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external SQL files, which could contain hidden instructions targeting the agent's reasoning during validation.
- Ingestion points: Migration files (.up.sql and .down.sql) are loaded using the Read tool in Step 2.
- Capability inventory: The agent has access to Bash, file system tools (Glob, Grep, Read), and multiple memory storage plugins.
- Boundary markers: The skill does not provide specific instructions or delimiters to isolate user-provided SQL content from the agent's internal logic.
- Sanitization: There is no description of filtering or sanitizing the SQL content before it is parsed and reported by the agent.
Audit Metadata