data-analysis
Fail
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The resource
references/knowledge-base.mdcontains a URL togetmonetizely.comwhich has been flagged as a phishing domain by automated security scanners. - [DATA_EXFILTRATION]: Automated antivirus scans identified the file
references/knowledge-base.mdas infected with theMD:HttpRequest-infsignature, which is associated with malicious network activity or data exfiltration attempts. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by design as it ingests and processes arbitrary user datasets and dashboard metadata.
- Ingestion points: Dataset uploads and database connections mentioned in
SKILL.mdworkflows. - Boundary markers: Absent. The instructions do not define boundaries or specific directives for the agent to ignore instructions found within processed data.
- Capability inventory: Python script execution and SQL query execution are core capabilities for processing user data.
- Sanitization: Absent. The skill does not mandate sanitization or validation of the data content before analysis.
- [REMOTE_CODE_EXECUTION]: The skill's 'Hands-on Execution' workflow explicitly directs the agent to execute Python and SQL code based on external data, creating an execution surface for any malicious payloads embedded in that data.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata