geospatial-data-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data formats (GeoJSON and GPS tracks) and possesses file-write capabilities, creating a surface for indirect prompt injection attacks where malicious instructions hidden in data properties could influence the agent. • Ingestion points: The skill reads GeoJSON and GPS data from the filesystem using fs.readFileSync in scripts/geospatial_processor.ts and scripts/tile_generator.ts. • Boundary markers: No explicit prompt boundary markers or instructions to ignore embedded commands are present in the processing logic. • Capability inventory: The skill includes file-writing capabilities via fs.writeFileSync in scripts/geospatial_processor.ts and scripts/tile_generator.ts. • Sanitization: While the skill validates JSON structure, it does not sanitize or filter property values within the GeoJSON features for potential natural language instructions.
  • [COMMAND_EXECUTION]: The documentation in references/postgis-guide.md provides examples for the PostgreSQL \copy ... FROM PROGRAM command, which allows shell command execution from the database engine. This documents high-risk administrative capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:42 PM
Security Audit — agent-trust-hub — geospatial-data-pipeline