database-design
Fail
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (HIGH): The skill exhibits a significant attack surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read local documentation files (e.g., database-selection.md, schema-design.md) and solicit database preferences from the user.
- Boundary markers: There are no defined delimiters or instructions to treat external data as non-executable text.
- Capability inventory: The skill's allowed tools include Write and Edit, which provide the agent with the ability to modify the project's file system based on potentially malicious instructions found in ingested data.
- Sanitization: No input validation or content filtering mechanisms are specified.
- [NO_CODE] (LOW): The skill consists exclusively of markdown instructions and metadata, with no accompanying executable script files detected.
Recommendations
- AI detected serious security threats
Audit Metadata