scikit-learn

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation in references/model_evaluation.md details how to save and load models using the pickle and joblib libraries. These functions perform deserialization of data and can be exploited to execute arbitrary code if an agent is instructed to load a malicious file provided by an external source.
  • [EXTERNAL_DOWNLOADS]: The SKILL.md and references/quick_reference.md files provide instructions for installing common data science packages including scikit-learn, pandas, numpy, matplotlib, seaborn, imbalanced-learn, and umap-learn. These are widely used, standard libraries in the Python ecosystem.
  • [PROMPT_INJECTION]: Several reference files and scripts describe loading data from external files (e.g., pd.read_csv('data.csv')). This represents an ingestion point for untrusted content. The skill lacks boundary markers or explicit warnings to the agent regarding the risks of processing instructions that might be embedded in these data sources, particularly when combined with data persistence tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 03:10 AM