postgresql-development-cloudbase
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from a PostgreSQL database through the
queryPgDatabasetool. The instructions do not provide explicit guidance for the agent to treat these tool outputs as untrusted data or to utilize boundary markers when processing database records. This creates an attack surface where malicious instructions stored in the database could influence agent behavior, especially given the skill's extensive capabilities for database and environment management. - Ingestion points: SQL query results and schema information retrieved via
queryPgDatabase(referenced in SKILL.md and app-workflow.md). - Boundary markers: The instructions do not define delimiters or specific warnings for the agent when processing data returned from the database.
- Capability inventory: The skill provides access to powerful tools including
managePgDatabase(SQL execution),manageAppAuth(credential management), andmanageEnv(environment configuration). - Sanitization: No explicit logic or filtering instructions are provided to sanitize external content retrieved from database tables before interpolation into prompts.
- [SAFE]: All external URLs and resources mentioned, such as
tcloudbasegateway.comandcloudbase.net, are official infrastructure belonging to the vendortencentcloudbaseand do not represent a security risk. - [SAFE]: The skill promotes security best practices, specifically warning against the exposure of
service_roleAPI keys in frontend code and providing detailed templates for Row-Level Security (RLS) and table-level GRANTs.
Audit Metadata