ai-data-engineering
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
references/langchain-patterns.mdfile includes a code pattern for acalculator_toolthat utilizes theeval()function. This function executes arbitrary Python code from strings, creating a severe vulnerability to remote code execution (RCE) if the agent processes untrusted input through this tool. - [CREDENTIALS_UNSAFE]: The documentation in
references/data-versioning.mdcontains hardcoded sample AWS access keys (AKIAIOSFOLQUICKSTARTand a sample secret key). While these are standard documentation placeholders, they trigger high-severity security detections and represent poor secret management practice. - [COMMAND_EXECUTION]: The implementation in
examples/feast-features/setup_features.pyutilizesos.system()to execute shell commands for initializing and applying feature store configurations. Spawning shell processes viaos.system()is a risky pattern that can lead to command injection if inputs are not strictly controlled. - [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to build RAG pipelines that ingest external documents (PDF, Markdown, HTML) and inject them into LLM prompts without implementing content sanitization or robust instruction boundaries.
- Ingestion points: Document loaders in
examples/dagster-pipelines/embedding_pipeline.py(loading from a source directory) andexamples/langchain-rag/main.py(usingTextLoader). - Boundary markers: Missing or inadequate; prompt templates use standard delimiters but lack explicit instructions for the model to ignore embedded malicious commands within the retrieved context.
- Capability inventory: The skill uses vector database writes, LLM generation, and file system operations.
- Sanitization: No evidence of content filtering or sanitization was found in the provided implementation examples.
Recommendations
- AI detected serious security threats
Audit Metadata