relational-database-mcp-cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate guidance for utilizing database management tools provided by tencentcloudbase. It emphasizes safety protocols for environment-level impacts, including provisioning and destruction flows that require confirmation and status polling. The recommendation to include the _openid column for per-user access control aligns with security best practices for cloud-based relational databases.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external SQL databases, creating a potential attack surface for indirect prompt injection. \n
  • Ingestion points: Tool outputs from queryMysqlDatabase(action='runQuery') and queryMysqlDatabase(action='getInstanceInfo') are integrated into the agent context.\n
  • Boundary markers: The skill lacks explicit instructions to treat data as untrusted or to ignore embedded instructions, though it recommends limited SELECT queries and manual review of result sets.\n
  • Capability inventory: The agent possesses extensive capabilities, including executing SQL mutations (INSERT/UPDATE/DELETE/DDL) via manageMysqlDatabase, modifying database permissions via managePermissions, and destroying database instances.\n
  • Sanitization: No specific mechanisms for escaping or sanitizing retrieved SQL data before processing are detailed in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — relational-database-mcp-cloudbase