skills/aeondave/malskill/scikit-learn/Gen Agent Trust Hub

scikit-learn

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for ingesting and processing external model artifacts which can be controlled by an attacker.
  • Ingestion points: The skill uses joblib.load() and sio.load() to read data from external files (model.joblib, model.skops).
  • Boundary markers: The instructions include explicit warnings for the agent to distinguish between trusted and untrusted files.
  • Capability inventory: The skill utilizes Python execution to perform model introspection, parameter extraction, and tree visualization.
  • Sanitization: The skill recommends using skops.io for untrusted artifacts, which implements a security-focused loading mechanism with explicit type allowlisting.
  • [DYNAMIC_EXECUTION]: The skill involves the deserialization of Python objects, which is a form of dynamic execution.
  • Evidence: The skill documents the use of joblib and pickle for loading estimators. The author includes a 'Caveats' section in SKILL.md stating that joblib.load and pickle are unsafe for untrusted files due to potential code execution during deserialization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — scikit-learn