data-analysis

Fail

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The resource references/knowledge-base.md contains a URL to getmonetizely.com which has been flagged as a phishing domain by automated security scanners.
  • [DATA_EXFILTRATION]: Automated antivirus scans identified the file references/knowledge-base.md as infected with the MD:HttpRequest-inf signature, which is associated with malicious network activity or data exfiltration attempts.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by design as it ingests and processes arbitrary user datasets and dashboard metadata.
  • Ingestion points: Dataset uploads and database connections mentioned in SKILL.md workflows.
  • Boundary markers: Absent. The instructions do not define boundaries or specific directives for the agent to ignore instructions found within processed data.
  • Capability inventory: Python script execution and SQL query execution are core capabilities for processing user data.
  • Sanitization: Absent. The skill does not mandate sanitization or validation of the data content before analysis.
  • [REMOTE_CODE_EXECUTION]: The skill's 'Hands-on Execution' workflow explicitly directs the agent to execute Python and SQL code based on external data, creating an execution surface for any malicious payloads embedded in that data.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 29, 2026, 10:19 PM
Security Audit — agent-trust-hub — data-analysis