plsql-apply

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading and processing external PL/SQL files, which represents an ingestion surface for untrusted data. This is appropriately managed by the skill's core architecture.
  • Ingestion points: The content of files processed by pythia apply <file> (SKILL.md).
  • Boundary markers: The skill mandates relaying tool output verbatim to the developer (Step 2) and explicitly forbids proceeding without a fresh 'yes' (Step 3).
  • Capability inventory: Execution of python scripts/pythia.py for database writes and journaled restores (SKILL.md).
  • Sanitization: Relies on human review and confirmation of the computed impact and diff rather than automated sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:08 AM
Security Audit — agent-trust-hub — plsql-apply