motherduck-ducklake
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing decision-making frameworks and SQL code snippets for MotherDuck storage management. It does not perform any autonomous actions, file system modifications, or network requests.
- [DATA_EXFILTRATION]: No evidence of sensitive data access or unauthorized exfiltration. SQL examples use generic placeholders (e.g., 's3://my-bucket/'), and the documented 'ATTACH' protocol ('ducklake:md:...') is a standard feature of the MotherDuck platform provided by the vendor.
- [REMOTE_CODE_EXECUTION]: The skill does not include any remote script downloads, package installations, or dynamic execution patterns that could lead to unauthorized code execution.
Audit Metadata