db-truth
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard operational guidelines for database management. It encourages 'grounding' AI actions in reality by verifying schemas directly from the database rather than relying on stale documentation or memory.
- [COMMAND_EXECUTION]: The skill mentions common database tools like
psql,npx supabase, andgrep. These are used for legitimate schema inspection (\d <table>), migration listing (supabase migration list), and codebase searching. These commands are typical for developer-focused skills and are directed toward the user's own environment/stack. - [CREDENTIALS_UNSAFE]: While the skill mentions environment variables and credentials (e.g.,
npx supabase status -o env), it does so in the context of suggesting safe management practices (such as using local stack credentials) and does not contain hardcoded secrets or instructions to exfiltrate them. - [DATA_EXFILTRATION]: No evidence of unauthorized data transfer was found. The network operations mentioned (via Supabase CLI) are standard for interacting with a user's own database infrastructure.
Audit Metadata