surrealdb-cli

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documents installation procedures that download scripts from https://install.surrealdb.com and https://windows.surrealdb.com for execution via shell and PowerShell respectively. These are the official distribution channels managed by the vendor.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use the surreal CLI binary to perform database operations such as starting servers, executing SQL, importing/exporting data, and upgrading the tool itself.
  • [EXTERNAL_DOWNLOADS]: References official software distribution points including the vendor's dedicated installation domain, the official Homebrew repository, and the surrealdb/surrealdb Docker image.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly advises against passing passwords or tokens as command-line flags to avoid exposure in process trees or shell history, instead recommending the use of standard environment variables like SURREAL_USER and SURREAL_PASS.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 05:09 PM
Security Audit — agent-trust-hub — surrealdb-cli