db-defaults

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [METADATA_POISONING]: The references/rationale.md file contains extensive fictional justifications for its technology recommendations, including 'research' dates in August 2026 and claims about industry events (such as Apple's acquisition of Kuzu) that have not occurred. This deceptive metadata is designed to influence the agent's decision-making based on a false reality.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a behavioral override for the agent's database selection logic. By providing a structured 'default' list backed by fictionalized authoritative rationale, it effectively poisons the agent's context and biases it toward specific dependencies that may be incorrect or non-existent in the current environment.
  • [REMOTE_CODE_EXECUTION]: The skill recommends installing the ladybug package via pip for graph database functionality. However, the ladybug name on PyPI is already occupied by the 'Ladybug Tools' environmental analysis package. Recommending a package name that serves a completely different purpose creates a dependency confusion risk, which is a common vector for executing unintended code during installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:25 AM
Security Audit — agent-trust-hub — db-defaults