dataset-transformation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Orchestrates data movement by executing shell commands via
subprocess.run, specifically utilizing the AWS CLI (aws s3 cp) to transfer datasets between Amazon S3 buckets and the local file system. - [DYNAMIC_EXECUTION]: Implements a workflow that dynamically generates Python transformation functions and execution scripts. These are saved to disk and executed using the
python3interpreter to validate the transformation logic against sample data records. - [INDIRECT_PROMPT_INJECTION]: Ingests and processes untrusted data from user-provided datasets. The skill lacks explicit sanitization or boundary markers when presenting sample records in the agent's context, which could allow malicious instructions embedded in a dataset to influence the agent's behavior.
- Ingestion points: Reads sample records from local or S3-hosted datasets in
SKILL.mdStep 5 and Step 11. - Boundary markers: None identified in the instructions for displaying sample records.
- Capability inventory: Subprocess shell execution, file system write access, and dynamic Python code execution.
- Sanitization: No validation or filtering of dataset content is performed before processing or display.
- [EXTERNAL_DOWNLOADS]: Fetches the latest evaluation dataset schema definitions from official AWS documentation at
docs.aws.amazon.com.
Audit Metadata