Create database migration
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
pnpmto create, test, and verify database migrations (e.g.,pnpm migrate:create,pnpm knex-migrator migrate). These are standard developer operations within the Ghost (tryghost) ecosystem and are executed within the localghost/coredirectory. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided task descriptions to generate database schema changes, which introduces a potential surface for indirect injection via malicious task descriptions.
- Ingestion points: The skill ingests user instructions, feature requests, and references to Linear issues as triggers for creating migrations (SKILL.md).
- Boundary markers: None explicitly defined in the provided instructions.
- Capability inventory: The agent is authorized to perform file modifications and shell command execution using the project's migration tools.
- Sanitization: The skill relies on the agent following the explicit instruction to use a 'kebab-case-slug' for migration names, which limits the potential for command injection through the migration script argument.
Audit Metadata