relational-database-mcp-cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary SQL statements, including data definition language (DDL) and destructive operations like DROP or DELETE, through the manageMysqlDatabase tool. Evidence: The runStatement action in SKILL.md is explicitly documented for this purpose.
  • [CREDENTIALS_UNSAFE]: The queryMysqlDatabase tool provides an action named getConnectionInfo which returns database connection details that the skill notes may include credentials. Evidence: This capability is documented in the tool description within SKILL.md, although accompanied by a warning against its use in new applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data queried from relational databases which could contain malicious instructions if the database content is sourced from untrusted users. Ingestion points: Results from queryMysqlDatabase(action='runQuery') are ingested into the agent context. Boundary markers: The skill does not provide specific instructions to delimit or ignore instructions found within data results. Capability inventory: The agent has capabilities to modify database state (manageMysqlDatabase), adjust security rules (managePermissions), and access connection info (queryMysqlDatabase). Sanitization: No sanitization or validation of SQL query results is specified before processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:51 AM
Security Audit — agent-trust-hub — relational-database-mcp-cloudbase