machine-learning
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external tabular data, which defines an attack surface for indirect prompt injection. However, the risk is minimal because the skill lacks the necessary capabilities to perform harmful actions even if malicious instructions were present in the data. All operations are confined to mathematical transformations and model fitting using established libraries.\n
- Ingestion points: Tabular data (features and target columns) are ingested into the agent context in SKILL.md and references/pipelines-and-cv.md.\n
- Boundary markers: Absent; the content of the tabular data is not wrapped in security-specific delimiters.\n
- Capability inventory: The skill uses scikit-learn, XGBoost, and LightGBM for modeling. It does not utilize tools for network access, file system modification, or shell command execution.\n
- Sanitization: Standard data preprocessing steps (imputation, scaling, encoding) are implemented via Pipeline and ColumnTransformer objects.\n- [SAFE]: No malicious patterns such as prompt injection, persistence mechanisms, or credential exfiltration were detected. The skill correctly references official documentation and trusted research sources.
Audit Metadata