data-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external CSV data to generate reports and dashboards, creating a potential surface for indirect prompt injection if the data contains malicious instructions targeted at the agent.
  • Ingestion points: Data enters the agent's context through scripts/analyze_missing_values.py, scripts/impute_missing_values.py, and scripts/create_dashboard.py, all of which read CSV files using pandas.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings for the data being processed.
  • Capability inventory: The skill scripts perform file write operations (JSON, CSV, and HTML) and launch a local network server for interactive Dash dashboards.
  • Sanitization: The scripts do not appear to perform specific sanitization or filtering of text content within the CSV data before presenting it or using it in visualizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:00 AM
Security Audit — agent-trust-hub — data-analyst