arize-dataset
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [METADATA_POISONING]: The skill metadata lists 'arize' as the author, which conflicts with the provided author context identifying 'ethan-rio' as the author. This discrepancy is a form of deceptive metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill provides commands such as
ax datasets createandax datasets appendthat ingest untrusted data from various file formats and strings. The evidence chain includes: 1) Ingestion points for external data via the--fileand--jsonflags; 2) A lack of explicit boundary markers or instructions to ignore instructions within that data; 3) Capabilities to execute CLI commands and interact with the filesystem; 4) No mentioned sanitization or validation of the data contents. This surface allows for potential multi-step attacks if malicious data influences the agent's behavior. - [PERSISTENCE]: In
references/ax-profiles.md, the skill instructs users on how to persist environment variables by modifying shell profiles like~/.zshrcor~/.bashrc. While this is intended for legitimate configuration of theARIZE_SPACEvariable for the CLI tool, it represents a mechanism for maintaining persistent configuration across sessions.
Audit Metadata