alterlab-missing-data

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill enables processing of untrusted external datasets using execution tools like Bash and Python. It lacks protective measures like boundary markers or input sanitization, allowing potential malicious content in data to influence agent behavior.\n
  • Ingestion points: Reads and processes external datasets in Python and R (SKILL.md, references/mechanisms_and_pooling.md).\n
  • Boundary markers: Absent; no delimiters used to separate data from instructions.\n
  • Capability inventory: Full access to Bash and Read tools for statistical operations.\n
  • Sanitization: Not provided; data is passed directly to analysis functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 11:26 PM
Security Audit — agent-trust-hub — alterlab-missing-data