smart-query

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill requires database and SSH credentials to be stored in config/settings.json. The example file and the loading logic in scripts/db_connector.py facilitate the storage of usernames, passwords, and private key paths in plain text within the skill's directory.
  • [COMMAND_EXECUTION]: The script scripts/query.py accepts raw SQL strings from command-line arguments and executes them against the database. Although the skill instructions advise the agent to limit its actions to SELECT queries, the code explicitly supports state-changing operations by calling conn.commit() for SQL statements that do not begin with SELECT, SHOW, or DESC.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as its core logic involves the agent reading and acting upon potentially untrusted data from the database schema and query results.
  • Ingestion points: The agent ingests external data from the references/schema.md file (generated from the database) and from the raw output of database queries performed via scripts/query.py.
  • Boundary markers: The SKILL.md file provides natural language instructions for the agent to limit itself to specific query types, but there are no technical enforcement mechanisms or delimiters in the scripts to prevent the execution of malicious instructions embedded in database content.
  • Capability inventory: The skill possesses the capability to establish network connections through SSH tunnels and execute arbitrary database commands using the provided scripts.
  • Sanitization: There is no evidence of SQL sanitization or the use of parameterized queries; the agent's natural language intent is converted to a string that is executed directly as a shell-driven SQL command.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — smart-query