Create database migration

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using pnpm to create, test, and verify database migrations (e.g., pnpm migrate:create, pnpm knex-migrator migrate). These are standard developer operations within the Ghost (tryghost) ecosystem and are executed within the local ghost/core directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided task descriptions to generate database schema changes, which introduces a potential surface for indirect injection via malicious task descriptions.
  • Ingestion points: The skill ingests user instructions, feature requests, and references to Linear issues as triggers for creating migrations (SKILL.md).
  • Boundary markers: None explicitly defined in the provided instructions.
  • Capability inventory: The agent is authorized to perform file modifications and shell command execution using the project's migration tools.
  • Sanitization: The skill relies on the agent following the explicit instruction to use a 'kebab-case-slug' for migration names, which limits the potential for command injection through the migration script argument.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 08:34 AM