relational-database-mcp-cloudbase
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [Indirect Prompt Injection] (SAFE): The skill describes a surface for processing untrusted data from database tables.
- Ingestion points: Results returned from
executeReadOnlySQLqueries (defined inSKILL.md). - Boundary markers: Absent; there are no specific delimiters or instructions provided to the agent to differentiate between data and instructions within query results.
- Capability inventory: The agent has access to
executeWriteSQL(DML/DDL) andwriteSecurityRule(permission management), which are high-impact capabilities. - Sanitization: Absent; the skill relies on the agent's internal reasoning and manual confirmation steps ('summarize what you are about to run') rather than technical sanitization.
- [Command Execution] (SAFE): The skill provides the
executeWriteSQLtool, which allows for the execution of arbitrary SQL commands including data modification and schema changes. This is identified as the primary intended purpose of the skill for database administration and management. - [Privilege Escalation] (SAFE): The skill provides
writeSecurityRule, a capability to modify access control lists on database tables. This is an administrative function consistent with the skill's stated purpose of database management.
Audit Metadata