skills/jeremylongshore/claude-code-plugins-plus-skills/managing-database-sharding/Gen Agent Trust Hub
managing-database-sharding
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and analyze output from database command-line tools. * Ingestion points: Data enters the agent's context through the output of psql, mysql, and mongosh queries used for distribution analysis (SKILL.md). * Boundary markers: There are no explicit delimiters or instructions provided to the agent to differentiate between untrusted database content and its own operating instructions. * Capability inventory: The agent has permissions to execute restricted shell commands (psql, mysql, mongosh) and perform file write/edit operations (SKILL.md). * Sanitization: The skill does not implement any mechanisms to sanitize or validate database output before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill includes documentation links for Citus, Vitess, MongoDB, and ProxySQL (SKILL.md). These resources are from well-known and trusted technology organizations and are used appropriately for educational and configuration guidance.
Audit Metadata