NYC

mysql

Warn

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS] (MEDIUM): The skill's workflow depends on fetching reference material from external URLs from a non-whitelisted source.\n
  • Evidence: SKILL.md contains instructions to 'Read only the relevant reference files linked in each section below' and provides eighteen absolute URLs to 'https://raw.githubusercontent.com/planetscale/database-skills/...'.\n
  • Risk: The 'planetscale' GitHub organization is not on the whitelisted 'Trusted GitHub Organizations' list. Loading instructions dynamically from unverified external sources is a security risk as the remote content could be modified to include malicious instructions or bypass safety guidelines (Indirect Prompt Injection).\n- [COMMAND_EXECUTION] (SAFE): The skill documentation includes various SQL commands (e.g., ALTER TABLE, SET GLOBAL, ANALYZE TABLE). These are presented as educational templates for user review and do not constitute arbitrary command execution by the agent itself.\n- [DATA_EXFILTRATION] (SAFE): No unauthorized network operations or hardcoded credentials were found. The use of MySQL metadata tables (information_schema, performance_schema) is standard for the skill's intended purpose of database optimization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 04:17 PM