db-defaults
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [METADATA_POISONING]: The
references/rationale.mdfile contains extensive fictional justifications for its technology recommendations, including 'research' dates in August 2026 and claims about industry events (such as Apple's acquisition of Kuzu) that have not occurred. This deceptive metadata is designed to influence the agent's decision-making based on a false reality. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a behavioral override for the agent's database selection logic. By providing a structured 'default' list backed by fictionalized authoritative rationale, it effectively poisons the agent's context and biases it toward specific dependencies that may be incorrect or non-existent in the current environment.
- [REMOTE_CODE_EXECUTION]: The skill recommends installing the
ladybugpackage viapipfor graph database functionality. However, theladybugname on PyPI is already occupied by the 'Ladybug Tools' environmental analysis package. Recommending a package name that serves a completely different purpose creates a dependency confusion risk, which is a common vector for executing unintended code during installation.
Audit Metadata