tuner
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data, including database execution plans (EXPLAIN ANALYZE), slow query logs, and SQL query patterns. This ingestion constitutes an attack surface where an attacker could embed malicious instructions within the data to influence the agent's diagnostics or the fix prompts it generates for downstream agents.
- Ingestion points: Database execution plans and workload context described in
SKILL.mdandreference/explain-analyze-guide.mdare analyzed at runtime. - Boundary markers: The skill instructions do not mandate specific delimiters or "ignore instructions" wrappers for the ingested logs or plan data, though it emphasizes structured phases.
- Capability inventory: The skill generates DDL recommendations (e.g.,
CREATE INDEX), query rewrites, and## LLM Fix Promptblocks intended for execution by other agents (Builder, Schema, Bolt). - Sanitization: The "Core Contract" in
SKILL.mdand the guidelines inreference/fix-prompt-generation.mdrecommend parameterizing secrets and literals and requiring plan-evidence validation, providing a degree of manual mitigation.
Audit Metadata