skills/witooh/skills/state-db/Gen Agent Trust Hub

state-db

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from an external PostgREST database. An attacker who gains access to the database could inject malicious instructions into the stored state, which the agent might then interpret as authoritative commands when retrieved.
  • Ingestion points: Records are fetched from the skill_state table via curl GET requests in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or warnings to treat retrieved database content as untrusted.
  • Capability inventory: The skill utilizes shell execution for database interactions (curl) and token generation (python3).
  • Sanitization: No explicit data sanitization or validation of the retrieved JSONB payload is implemented.
  • [DYNAMIC_EXECUTION]: The skill uses a python3 command to dynamically generate a JSON Web Token (JWT) for authentication. While the script is a fixed template using local environment variables, the use of inline script execution is a form of dynamic code generation.
  • Evidence: The DB_TOKEN assignment in SKILL.md executes an inline Python script to handle HMAC signing and Base64 encoding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:57 PM
Security Audit — agent-trust-hub — state-db