data-fair-processing

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates and instructions for executing system commands (e.g., using unzip). It explicitly recommends using execFile with argument arrays instead of shell strings to prevent shell injection vulnerabilities in lib/execute.ts and file-templates.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for processing external data sources (CSV, GTFS, ZIP). While it handles untrusted data ingestion in lib/download.ts and lib/process.ts, it provides a structured approach for validation and processing, mitigating risks by scoping file operations to a temporary directory (tmpDir) and utilizing specific boundary markers like ProcessingContext.
  • [EXTERNAL_DOWNLOADS]: The skill references standard dependency management via npm and the use of official GitHub Actions from the data-fair organization for plugin deployment to their registry. These references are consistent with the vendor's ecosystem and utilize trusted sources.
  • [CREDENTIALS_UNSAFE]: The documentation in SKILL.md and config-schema.md outlines a secure pattern for handling secrets, requiring a prepare step to move sensitive values from the user-facing configuration to a restricted secrets context, ensuring they are not stored in plain text in the main configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:56 PM
Security Audit — agent-trust-hub — data-fair-processing