data-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, potentially untrusted data files and SQL queries through its internal Python scripts. This creates a surface for indirect prompt injection where malicious instructions embedded in data files could influence the agent's behavior during analysis or report generation.\n
  • Ingestion points: Data enters the agent context through the --file and --sql arguments used by scripts/data_profiler.py, scripts/report_generator.py, and scripts/query_optimizer.py.\n
  • Boundary markers: The skill does not employ specific delimiters or 'ignore' instructions for the data being processed, which increases the likelihood of the agent inadvertently following instructions found within the data.\n
  • Capability inventory: The provided scripts perform statistical profiling, numerical aggregation, and regex-based SQL analysis. None of the scripts possess network connectivity or access to sensitive system directories.\n
  • Sanitization: While the scripts use standard libraries for parsing CSV and JSON, they do not include mechanisms to sanitize the content for embedded natural language instructions before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:13 AM
Security Audit — agent-trust-hub — data-analyst