data-sql-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a utility script scripts/explain_collector.py that utilizes subprocess.run to call the psql command-line tool. This is the intended functionality to collect execution plans from PostgreSQL databases. The script invokes the binary using an argument list rather than a shell string, which is a secure practice for calling external utilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze SQL queries provided by users, creating a surface for indirect injection. However, the execution script scripts/explain_collector.py mitigates the risk of accidental data modification by wrapping the queries in a transaction that is explicitly rolled back (ROLLBACK) after the EXPLAIN ANALYZE command is executed.
  • [EXTERNAL_DOWNLOADS]: The skill references several external documentation sources and tools within data/sources.json. These references target official and well-known services, including the primary documentation for PostgreSQL, MySQL, Microsoft SQL Server, Oracle, and SQLite, as well as trusted educational publishers like Manning and O'Reilly. These resources are provided for developer reference and fact-checking purposes.
  • [SAFE]: The documentation within the skill emphasizes secure database practices, such as the use of parameterized queries to prevent SQL injection and the implementation of least-privilege access controls via Row-Level Security (RLS).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:38 PM
Security Audit — agent-trust-hub — data-sql-optimization