ml-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill templates utilize
pickle.loadandjoblib.loadfor serializing and deserializing machine learning models. While these methods are susceptible to unsafe deserialization if loading untrusted files, their use here is consistent with standard machine learning infrastructure practices. The code examples demonstrate loading models from temporary local paths or established model registries, which is the primary intended function of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill features data ingestion surfaces where the agent is instructed to read external datasets (CSV, Parquet) from user-defined paths. Although this presents an attack surface where malicious data could influence agent decisions, the skill mitigates this by emphasizing rigorous data validation using tools like Great Expectations before processing.
- Ingestion points: Data is loaded via
pd.read_csvandpd.read_parquetinreferences/pipeline-orchestration.mdandreferences/training-pipelines.md. - Boundary markers: The instructions mandate schema validation steps to halt the pipeline on failures.
- Capability inventory: The skill has capabilities for file system writes (
to_parquet,joblib.dump) and network operations via official SDKs for MLflow, WandB, and GCS. - Sanitization: Validation checkpoints are explicitly implemented in the
Data Validation CheckpointandGreat Expectationstemplates.
Audit Metadata