senior-data-scientist

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its data processing scripts.
  • Ingestion points: The scripts scripts/experiment_designer.py, scripts/feature_engineering_pipeline.py, and scripts/model_evaluation_suite.py all accept an --input argument intended for reading external data files into the agent's context.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious instructions embedded within the data files it processes.
  • Capability inventory: While the scripts currently contain boilerplate code with no active dangerous operations, they are designed to be part of a workflow that includes model evaluation and deployment.
  • Sanitization: The provided script templates do not implement any data validation or sanitization logic to mitigate risks from untrusted inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 09:59 AM
Security Audit — agent-trust-hub — senior-data-scientist