scikit-learn
Warn
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation in
references/model_evaluation.mddetails how to save and load models using thepickleandjobliblibraries. These functions perform deserialization of data and can be exploited to execute arbitrary code if an agent is instructed to load a malicious file provided by an external source. - [EXTERNAL_DOWNLOADS]: The
SKILL.mdandreferences/quick_reference.mdfiles provide instructions for installing common data science packages includingscikit-learn,pandas,numpy,matplotlib,seaborn,imbalanced-learn, andumap-learn. These are widely used, standard libraries in the Python ecosystem. - [PROMPT_INJECTION]: Several reference files and scripts describe loading data from external files (e.g.,
pd.read_csv('data.csv')). This represents an ingestion point for untrusted content. The skill lacks boundary markers or explicit warnings to the agent regarding the risks of processing instructions that might be embedded in these data sources, particularly when combined with data persistence tools.
Audit Metadata