exploratory-data-analysis
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests and processes untrusted scientific data across 200+ formats (e.g., .fastq, .csv, .pdb) as described in the Workflow sections. It lacks explicit instructions for the agent to use boundary markers or sanitization when interpolating this external data into reports or subsequent analysis steps, which is a characteristic of indirect prompt injection surfaces. Evidence: Workflow Step 3 (Perform Data Analysis) and Step 4 (Generate Comprehensive Report) in SKILL.md.
- [COMMAND_EXECUTION]: The skill facilitates the execution of a local Python script and various third-party libraries to perform complex data analysis on user-provided files. Evidence: Section 'Script Usage' and 'Workflow Step 3' in SKILL.md.
Audit Metadata