skills/simota/agent-skills/tuner/Gen Agent Trust Hub

tuner

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data, including database execution plans (EXPLAIN ANALYZE), slow query logs, and SQL query patterns. This ingestion constitutes an attack surface where an attacker could embed malicious instructions within the data to influence the agent's diagnostics or the fix prompts it generates for downstream agents.
  • Ingestion points: Database execution plans and workload context described in SKILL.md and reference/explain-analyze-guide.md are analyzed at runtime.
  • Boundary markers: The skill instructions do not mandate specific delimiters or "ignore instructions" wrappers for the ingested logs or plan data, though it emphasizes structured phases.
  • Capability inventory: The skill generates DDL recommendations (e.g., CREATE INDEX), query rewrites, and ## LLM Fix Prompt blocks intended for execution by other agents (Builder, Schema, Bolt).
  • Sanitization: The "Core Contract" in SKILL.md and the guidelines in reference/fix-prompt-generation.md recommend parameterizing secrets and literals and requiring plan-evidence validation, providing a degree of manual mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — tuner