data-scientist
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from the project environment, including source code, architecture documents, and analytics data. This creates a surface for indirect prompt injection where malicious instructions embedded in these files could influence the agent's behavior.
- Ingestion points: Project source code,
.forgewright/product-manager/files, infrastructure monitoring data, and architecture documentation are accessed in Phase 1 (system-audit.md). - Boundary markers: The skill does not explicitly define delimiters or specialized instructions to ignore embedded commands within the analyzed data to prevent accidental obedience.
- Capability inventory: The skill identifies and maps LLM API calls, ML models, and data pipelines, and is instructed to generate implementation code, which could be influenced by injected instructions.
- Sanitization: The instructions mention anonymizing PII in the 'Common Mistakes' section, but do not provide specific technical mechanisms for sanitizing incoming text from the analyzed codebase.
- [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (
!cat ...) inSKILL.mdto execute shell commands at load time to include content from external files. While the commands are benign (cat), they allow the skill to dynamically modify its system instructions based on the contents of local project files. - Evidence:
!cat skills/_shared/protocols/ux-protocol.md,!cat .production-grade.yaml, and!cat .forgewright/settings.mdare used to load configuration and protocol details into the agent's prompt context.
Audit Metadata