ent-seed-sql-generator

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python code snippets in 'references/password-hashing.md' to generate bcrypt and argon2 password hashes. These snippets are designed to be executed locally by the agent to ensure seed data contains valid credential hashes.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to ingest and process data from Go Ent schemas, migration files, and product documentation. * Ingestion points: The agent reads content from 'ent/schema/*.go', 'ent/client.go', and other project-related files. * Boundary markers: There are no instructions to use delimiters or 'ignore instructions' blocks within the ingested data. * Capability inventory: The skill can generate SQL artifacts and provide code snippets for execution. * Sanitization: The instructions do not specify any validation or sanitization of the ingested content before it is used for SQL generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 02:17 PM