sdmx-explorer
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
opensdmxandduckdbcommand-line interfaces to search, filter, and transform datasets. It also involves running Python code for advanced data visualization using theplotninelibrary. - [EXTERNAL_DOWNLOADS]: Includes instructions for installing the DuckDB CLI via its official distribution point (
https://install.duckdb.org | sh). This is a documented installation method for a well-known technology service. Additionally, it generates direct download URLs for data hosted by official government and international statistical organizations. - [INDIRECT_PROMPT_INJECTION]: The skill processes external metadata and data from SDMX providers. It possesses a potential attack surface due to the combination of untrusted data ingestion and exploitable capabilities (shell and Python execution). However, the skill provides clear structural boundaries and focused instructions for data exploration, and there is no evidence of adversarial intent.
Audit Metadata