marketing-mix-modeling-pipeline

Fail

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation section directs users to clone a repository from 'francescaetnom-wq', an unverified GitHub account that is not associated with the skill's stated author or any trusted organizations.
  • [REMOTE_CODE_EXECUTION]: The skill provides a sequence of commands to clone an external repository, install its dependencies, and execute Python code and Jupyter notebooks, which can lead to the execution of malicious scripts from an untrusted source.
  • [PROMPT_INJECTION]: The skill processes marketing data from a CSV file (dt_simulated_weekly.csv) without implementing sanitization or boundary markers, making it susceptible to indirect prompt injection if the data source is compromised. 1. Ingestion points: 'data/dt_simulated_weekly.csv' loaded via pandas. 2. Boundary markers: Absent. 3. Capability inventory: File writing capabilities through 'to_csv' and shell access via suggested 'git clone'. 4. Sanitization: Absent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 26, 2026, 08:40 PM
Security Audit — agent-trust-hub — marketing-mix-modeling-pipeline