skills/aiopshwang/data-analysis-ml-agent-skills/running-decision-grade-data-science/Gen Agent Trust Hub
running-decision-grade-data-science
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill does not contain any hardcoded credentials, API keys, or logic for accessing sensitive system files such as SSH keys or environment configurations.
- [SAFE]: No remote code execution patterns, unauthorized external downloads, or runtime package installations were identified in the skill instructions or supporting files.
- [SAFE]: No obfuscation techniques, such as Base64 encoding, hex escapes, or zero-width characters, were detected. The content is transparent and instructional.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of external data, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: The skill explicitly instructs the agent to inventory and preserve raw source files, tables, queries, and documentation (Step 1 of lifecycle in
SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the data being processed, which would help distinguish between data and instructions.
- Capability inventory: The agent is expected to perform file system operations and potentially execute analysis commands (e.g., in a notebook or terminal) to validate data and build baselines.
- Sanitization: There are no mentions of sanitizing external inputs or filtering for malicious instructions embedded within the datasets or metadata.
Audit Metadata