dbos-python

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): The skill contains legitimate reference material and code snippets for the DBOS framework. No security violations or malicious patterns were identified during the analysis.
  • [Indirect Prompt Injection] (LOW): The skill provides guidance on building applications that ingest untrusted data from external APIs (e.g., via FastAPI) and perform sensitive operations (e.g., database writes and network requests). While this presents an attack surface for indirect prompt injection in applications built following these guides, the skill itself does not contain malicious logic or insecure data handling. Evidence: Ingestion points in references/lifecycle-fastapi.md; Capability inventory includes network access in references/step-basics.md and database access in references/step-transactions.md; Boundary markers and Sanitization are not specifically defined in the instructional snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:25 PM