sdmx-explorer

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the opensdmx and duckdb command-line interfaces to search, filter, and transform datasets. It also involves running Python code for advanced data visualization using the plotnine library.
  • [EXTERNAL_DOWNLOADS]: Includes instructions for installing the DuckDB CLI via its official distribution point (https://install.duckdb.org | sh). This is a documented installation method for a well-known technology service. Additionally, it generates direct download URLs for data hosted by official government and international statistical organizations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external metadata and data from SDMX providers. It possesses a potential attack surface due to the combination of untrusted data ingestion and exploitable capabilities (shell and Python execution). However, the skill provides clear structural boundaries and focused instructions for data exploration, and there is no evidence of adversarial intent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 07:47 PM