db-truth

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard operational guidelines for database management. It encourages 'grounding' AI actions in reality by verifying schemas directly from the database rather than relying on stale documentation or memory.
  • [COMMAND_EXECUTION]: The skill mentions common database tools like psql, npx supabase, and grep. These are used for legitimate schema inspection (\d <table>), migration listing (supabase migration list), and codebase searching. These commands are typical for developer-focused skills and are directed toward the user's own environment/stack.
  • [CREDENTIALS_UNSAFE]: While the skill mentions environment variables and credentials (e.g., npx supabase status -o env), it does so in the context of suggesting safe management practices (such as using local stack credentials) and does not contain hardcoded secrets or instructions to exfiltrate them.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer was found. The network operations mentioned (via Supabase CLI) are standard for interacting with a user's own database infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 01:32 AM
Security Audit — agent-trust-hub — db-truth