recsys-pipeline-architect
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install components via 'npx skills add' from an external repository (mturac/recsys-pipeline-architect) that is not identified as a recognized official service or author-verified source.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates a code generation workflow using external data, creating an attack surface for indirect prompt injection.
- Ingestion points: User-provided use case clarifications and input context in SKILL.md.
- Boundary markers: Absent; the instructions do not define delimiters for user data.
- Capability inventory: Generation of runnable code scaffolds (SKILL.md).
- Sanitization: Absent; no validation requirements are defined for the interpolated user context.
- [DYNAMIC_EXECUTION]: The skill instructions direct the agent to generate functional code scaffolds in multiple languages (TypeScript, Go, Python) based on user-specified requirements, which represents a risk if the generation process is influenced by malicious input.
Audit Metadata