skills/simota/agent-skills/schema/Gen Agent Trust Hub

schema

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions emphasize security-first database design, specifically advocating for Row-Level Security (RLS) and composite keys with tenant_id to prevent cross-tenant data leakage in multi-tenant environments.
  • [SAFE]: The migration strategies provided, such as the 'expand-contract' pattern and the use of lock_timeout for DDL operations, are industry standard for preventing data loss and service outages.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a downstream consumer of data requirements from other agents (e.g., Builder, Gateway), which represents a vulnerability surface for indirect prompt injection.
  • Ingestion points: Data requirements and architectural context received from agents like Builder, Atlas, Gateway, Lens, and Sentinel.
  • Boundary markers: The instructions do not define specific delimiters for untrusted input ingestion.
  • Capability inventory: The skill generates DDL, migration scripts, and index strategies, but does not perform direct command execution or network calls.
  • Sanitization: None explicitly mentioned for handling external input, though output is restricted to structured SQL and schema definitions.
  • Severity: Low.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — schema