ml-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes components that ingest external data (e.g.,
pd.read_parquetandpd.read_csv) to drive training and feature engineering workflows. - Ingestion points: Data is loaded from paths specified in pipeline parameters or input datasets in
SKILL.mdandreferences/pipeline-orchestration.md. - Boundary markers: The skill explicitly recommends and provides templates for data validation checkpoints using
great_expectationsto verify schemas and distributions before processing. - Capability inventory: Scripts include model serialization and loading via
pickle,joblib, andtorch, as well as file operations for deployment. - Sanitization: Integrated validation logic reduces the risk of malicious data influencing agent behavior.
- [DYNAMIC_EXECUTION]: The provided templates utilize
pickle.load(),joblib.load(), andtorch.load()for deserializing models and transformation pipelines. - Evidence: Found in
references/feature-engineering.md(FeaturePipeline.load),references/pipeline-orchestration.md(evaluate_model), andreferences/training-pipelines.md(load_checkpoint). - Context: These are standard practices within MLOps for managing model artifacts; the skill's primary purpose is providing these infrastructure patterns for developer use.
Audit Metadata