vaex
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data, which creates a surface for indirect prompt injection.
- Ingestion points: Data is loaded from local or remote files via
vaex.open()andvaex.from_csv()as seen inreferences/io_operations.mdandreferences/core_dataframes.md. - Capability inventory: The skill can write files (
export_hdf5), train ML models, and perform complex data transformations across various scripts. - Boundary markers: No delimiters or instructions are present to prevent the agent from obeying instructions embedded within the processed data.
- Sanitization: The documentation does not provide methods for validating or sanitizing input data before processing.
- [COMMAND_EXECUTION]: The skill uses Numba JIT (
@numba.jit) to compile and execute custom Python logic at runtime for performance, as documented inreferences/performance.md. It also references thevaex-serverCLI tool inreferences/io_operations.md. - [EXTERNAL_DOWNLOADS]: The documentation includes patterns for accessing data from well-known cloud storage services, including Amazon S3, Google Cloud Storage, and Azure Blob Storage, using standard integration libraries.
Audit Metadata