skills/whopinak/how-to/db-architect/Gen Agent Trust Hub

db-architect

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in app ideas or PRDs.\n
  • Ingestion points: The skill ingests application concepts and Product Requirement Documents provided by users to generate architectural designs (SKILL.md).\n
  • Boundary markers: There are no defined delimiters or instructions to ignore embedded commands within the input text to prevent the agent from following malicious directives found in user input.\n
  • Capability inventory: The skill leverages file-writing capabilities to save generated SQL schemas to the local file system at docs/SCHEMA.md or via artifact creation (SKILL.md).\n
  • Sanitization: The instructions do not include requirements for validating or sanitizing the user-provided descriptions before they are incorporated into the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:06 PM
Security Audit — agent-trust-hub — db-architect