AgentDB Learning Plugins

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation suggests using npx agentdb@latest, which downloads and executes the agentdb package from the npm registry. These resources are part of the vendor's (ruvnet) official toolkit.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing training data that could potentially contain adversarial content.
  • Ingestion points: Data enters the system via the adapter.insertPattern method as shown in SKILL.md.
  • Boundary markers: The provided code snippets do not implement specific boundary markers or instructions to ignore embedded commands within the training data.
  • Capability inventory: The skill facilitates neural network training and inference via the adapter.train and adapter.retrieveWithReasoning methods.
  • Sanitization: The snippets demonstrate passing raw JSON data to the storage and training functions without explicit sanitization.
  • [COMMAND_EXECUTION]: The skill provides various CLI commands for managing plugins (e.g., create-plugin, list-templates). These are standard operational commands for the described toolset.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — AgentDB Learning Plugins