smart-query
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill requires database and SSH credentials to be stored in
config/settings.json. The example file and the loading logic inscripts/db_connector.pyfacilitate the storage of usernames, passwords, and private key paths in plain text within the skill's directory. - [COMMAND_EXECUTION]: The script
scripts/query.pyaccepts raw SQL strings from command-line arguments and executes them against the database. Although the skill instructions advise the agent to limit its actions toSELECTqueries, the code explicitly supports state-changing operations by callingconn.commit()for SQL statements that do not begin withSELECT,SHOW, orDESC. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as its core logic involves the agent reading and acting upon potentially untrusted data from the database schema and query results.
- Ingestion points: The agent ingests external data from the
references/schema.mdfile (generated from the database) and from the raw output of database queries performed viascripts/query.py. - Boundary markers: The
SKILL.mdfile provides natural language instructions for the agent to limit itself to specific query types, but there are no technical enforcement mechanisms or delimiters in the scripts to prevent the execution of malicious instructions embedded in database content. - Capability inventory: The skill possesses the capability to establish network connections through SSH tunnels and execute arbitrary database commands using the provided scripts.
- Sanitization: There is no evidence of SQL sanitization or the use of parameterized queries; the agent's natural language intent is converted to a string that is executed directly as a shell-driven SQL command.
Audit Metadata