database-design

Fail

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (HIGH): The skill exhibits a significant attack surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to read local documentation files (e.g., database-selection.md, schema-design.md) and solicit database preferences from the user.
  • Boundary markers: There are no defined delimiters or instructions to treat external data as non-executable text.
  • Capability inventory: The skill's allowed tools include Write and Edit, which provide the agent with the ability to modify the project's file system based on potentially malicious instructions found in ingested data.
  • Sanitization: No input validation or content filtering mechanisms are specified.
  • [NO_CODE] (LOW): The skill consists exclusively of markdown instructions and metadata, with no accompanying executable script files detected.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 17, 2026, 12:24 AM