database-optimizer

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation link 'https://jeffallan.github.io/claude-skills/skills/infrastructure/database-optimizer/' included in the skill is explicitly flagged by automated security scanners as malicious or blacklisted.
  • [METADATA_POISONING]: The main instruction file (SKILL.md) has been flagged by file reputation scanners with a malicious reputation score.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform high-privilege administrative SQL operations (e.g., 'ALTER SYSTEM SET', 'SET GLOBAL', 'CREATE INDEX CONCURRENTLY') that modify database system behavior and could lead to performance degradation or instability if misused.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted database query strings and execution plans, creating an injection surface. 1. Ingestion points: SQL query text and EXPLAIN ANALYZE results processed during optimization. 2. Boundary markers: Absent; there are no instructions to the agent to disregard instructions embedded within the SQL code or plan data. 3. Capability inventory: Execution of system-level database configuration changes. 4. Sanitization: Absent; the skill does not specify validation or filtering of the input query strings before processing.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 14, 2026, 09:34 PM
Security Audit — agent-trust-hub — database-optimizer