scikit-learn
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for ingesting and processing external model artifacts which can be controlled by an attacker.
- Ingestion points: The skill uses
joblib.load()andsio.load()to read data from external files (model.joblib,model.skops). - Boundary markers: The instructions include explicit warnings for the agent to distinguish between trusted and untrusted files.
- Capability inventory: The skill utilizes Python execution to perform model introspection, parameter extraction, and tree visualization.
- Sanitization: The skill recommends using
skops.iofor untrusted artifacts, which implements a security-focused loading mechanism with explicit type allowlisting. - [DYNAMIC_EXECUTION]: The skill involves the deserialization of Python objects, which is a form of dynamic execution.
- Evidence: The skill documents the use of
joblibandpicklefor loading estimators. The author includes a 'Caveats' section inSKILL.mdstating thatjoblib.loadand pickle are unsafe for untrusted files due to potential code execution during deserialization.
Audit Metadata