data-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, potentially untrusted data files and SQL queries through its internal Python scripts. This creates a surface for indirect prompt injection where malicious instructions embedded in data files could influence the agent's behavior during analysis or report generation.\n
- Ingestion points: Data enters the agent context through the
--fileand--sqlarguments used byscripts/data_profiler.py,scripts/report_generator.py, andscripts/query_optimizer.py.\n - Boundary markers: The skill does not employ specific delimiters or 'ignore' instructions for the data being processed, which increases the likelihood of the agent inadvertently following instructions found within the data.\n
- Capability inventory: The provided scripts perform statistical profiling, numerical aggregation, and regex-based SQL analysis. None of the scripts possess network connectivity or access to sensitive system directories.\n
- Sanitization: While the scripts use standard libraries for parsing CSV and JSON, they do not include mechanisms to sanitize the content for embedded natural language instructions before processing.
Audit Metadata