relational-database-mcp-cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary SQL statements, including data definition language (DDL) and destructive operations like DROP or DELETE, through the manageMysqlDatabase tool. Evidence: The runStatement action in SKILL.md is explicitly documented for this purpose.
- [CREDENTIALS_UNSAFE]: The queryMysqlDatabase tool provides an action named getConnectionInfo which returns database connection details that the skill notes may include credentials. Evidence: This capability is documented in the tool description within SKILL.md, although accompanied by a warning against its use in new applications.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data queried from relational databases which could contain malicious instructions if the database content is sourced from untrusted users. Ingestion points: Results from queryMysqlDatabase(action='runQuery') are ingested into the agent context. Boundary markers: The skill does not provide specific instructions to delimit or ignore instructions found within data results. Capability inventory: The agent has capabilities to modify database state (manageMysqlDatabase), adjust security rules (managePermissions), and access connection info (queryMysqlDatabase). Sanitization: No sanitization or validation of SQL query results is specified before processing by the agent.
Audit Metadata