data-sql-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a utility script
scripts/explain_collector.pythat utilizessubprocess.runto call thepsqlcommand-line tool. This is the intended functionality to collect execution plans from PostgreSQL databases. The script invokes the binary using an argument list rather than a shell string, which is a secure practice for calling external utilities. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze SQL queries provided by users, creating a surface for indirect injection. However, the execution script
scripts/explain_collector.pymitigates the risk of accidental data modification by wrapping the queries in a transaction that is explicitly rolled back (ROLLBACK) after theEXPLAIN ANALYZEcommand is executed. - [EXTERNAL_DOWNLOADS]: The skill references several external documentation sources and tools within
data/sources.json. These references target official and well-known services, including the primary documentation for PostgreSQL, MySQL, Microsoft SQL Server, Oracle, and SQLite, as well as trusted educational publishers like Manning and O'Reilly. These resources are provided for developer reference and fact-checking purposes. - [SAFE]: The documentation within the skill emphasizes secure database practices, such as the use of parameterized queries to prevent SQL injection and the implementation of least-privilege access controls via Row-Level Security (RLS).
Audit Metadata