dataset-transformation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Orchestrates data movement by executing shell commands via subprocess.run, specifically utilizing the AWS CLI (aws s3 cp) to transfer datasets between Amazon S3 buckets and the local file system.
  • [DYNAMIC_EXECUTION]: Implements a workflow that dynamically generates Python transformation functions and execution scripts. These are saved to disk and executed using the python3 interpreter to validate the transformation logic against sample data records.
  • [INDIRECT_PROMPT_INJECTION]: Ingests and processes untrusted data from user-provided datasets. The skill lacks explicit sanitization or boundary markers when presenting sample records in the agent's context, which could allow malicious instructions embedded in a dataset to influence the agent's behavior.
  • Ingestion points: Reads sample records from local or S3-hosted datasets in SKILL.md Step 5 and Step 11.
  • Boundary markers: None identified in the instructions for displaying sample records.
  • Capability inventory: Subprocess shell execution, file system write access, and dynamic Python code execution.
  • Sanitization: No validation or filtering of dataset content is performed before processing or display.
  • [EXTERNAL_DOWNLOADS]: Fetches the latest evaluation dataset schema definitions from official AWS documentation at docs.aws.amazon.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:58 PM
Security Audit — agent-trust-hub — dataset-transformation