postgresql-best-practices-cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill describes the use of platform-specific tools
queryPgDatabase,queryEnv, andapplyMigration. These tools are used for introspection, performance analysis, and schema management within the authorized CloudBase environment, serving the skill's primary educational and advisory purpose. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of user-provided SQL queries and application code snippets across all reference files. While no explicit boundary markers are mandated, the skill mitigates risk by documenting the platform's native sanitization, specifically noting that the
queryPgDatabasetool enforces a read-only gate that rejects potentially destructive commands likeANALYZEduring query estimation. - [DATA_EXFILTRATION]: Contains explicit security guidance in
references/capacity-and-connections.mdadvising users never to expose sensitive credentials such asSecretKey,API Key,service_role, or database connection strings in client-side code, which helps prevent accidental credential exposure. - [EXTERNAL_DOWNLOADS]: The main
SKILL.mdfile contains a security constraint that explicitly prohibits the agent from using HTTP to fetch remote skills or protocol markdown, restricting the context to local relative paths to maintain environment integrity.
Audit Metadata