AgentDB Advanced Features
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The documentation includes instructions for configuring the system firewall using
sudo ufw allow 4433/udp. While this requires administrative privileges, it is a standard operational step for enabling the QUIC protocol synchronization feature described in the skill. - [INDIRECT_PROMPT_INJECTION]: The skill exposes an attack surface through its data ingestion and retrieval functions, such as
insertPatternandretrieveWithReasoning, which process external or user-provided content. - Ingestion points: Data is ingested via
adapter.insertPatternand retrieved/processed viaadapter.retrieveWithReasoningas shown inSKILL.md. - Boundary markers: The provided code snippets do not explicitly show the use of delimiters or 'ignore' instructions for the data being processed.
- Capability inventory: The skill facilitates local database writes, network synchronization over QUIC, and CLI-based database management.
- Sanitization: There is no explicit evidence of data sanitization or schema validation for the
pattern_datametadata field in the examples. - [COMMAND_EXECUTION]: The skill documents the use of
npx agentdb@latestfor performing database operations like querying, importing, and exporting. This is the standard method for executing the vendor's command-line interface.
Audit Metadata