ml-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill templates utilize pickle.load and joblib.load for serializing and deserializing machine learning models. While these methods are susceptible to unsafe deserialization if loading untrusted files, their use here is consistent with standard machine learning infrastructure practices. The code examples demonstrate loading models from temporary local paths or established model registries, which is the primary intended function of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill features data ingestion surfaces where the agent is instructed to read external datasets (CSV, Parquet) from user-defined paths. Although this presents an attack surface where malicious data could influence agent decisions, the skill mitigates this by emphasizing rigorous data validation using tools like Great Expectations before processing.
  • Ingestion points: Data is loaded via pd.read_csv and pd.read_parquet in references/pipeline-orchestration.md and references/training-pipelines.md.
  • Boundary markers: The instructions mandate schema validation steps to halt the pipeline on failures.
  • Capability inventory: The skill has capabilities for file system writes (to_parquet, joblib.dump) and network operations via official SDKs for MLflow, WandB, and GCS.
  • Sanitization: Validation checkpoints are explicitly implemented in the Data Validation Checkpoint and Great Expectations templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — ml-pipeline