data-fair-processing
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates and instructions for executing system commands (e.g., using
unzip). It explicitly recommends usingexecFilewith argument arrays instead of shell strings to prevent shell injection vulnerabilities inlib/execute.tsandfile-templates.md. - [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for processing external data sources (CSV, GTFS, ZIP). While it handles untrusted data ingestion in
lib/download.tsandlib/process.ts, it provides a structured approach for validation and processing, mitigating risks by scoping file operations to a temporary directory (tmpDir) and utilizing specific boundary markers likeProcessingContext. - [EXTERNAL_DOWNLOADS]: The skill references standard dependency management via npm and the use of official GitHub Actions from the
data-fairorganization for plugin deployment to their registry. These references are consistent with the vendor's ecosystem and utilize trusted sources. - [CREDENTIALS_UNSAFE]: The documentation in
SKILL.mdandconfig-schema.mdoutlines a secure pattern for handling secrets, requiring apreparestep to move sensitive values from the user-facing configuration to a restrictedsecretscontext, ensuring they are not stored in plain text in the main configuration.
Audit Metadata