blink-database
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Executes database operations via the 'blink' CLI and specialized MCP tools. This is the core functionality intended for this database management skill.
- [SAFE]: Encourages the use of environment variables (e.g., 'process.env.NEXT_PUBLIC_BLINK_PUBLISHABLE_KEY') for handling sensitive credentials, which is a recommended security practice.
- [PROMPT_INJECTION]: The skill provides an interface for executing raw SQL queries, creating a potential surface for indirect prompt injection if the agent processes untrusted data. 1. Ingestion points: SQL query strings and filter parameters defined in 'SKILL.md'. 2. Boundary markers: No specific delimiters or warnings against embedded instructions are provided. 3. Capability inventory: Support for arbitrary SQL execution via 'blink_db_query'. 4. Sanitization: The provided examples do not demonstrate input validation or parameterized queries.
Audit Metadata