kaggle-learner

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external content and its application as executable logic.\n
  • Ingestion points: External Kaggle competition URLs provided by the user at runtime, processed by the kaggle-miner agent (as described in SKILL.md).\n
  • Boundary markers: None; the skill does not instruct the agent to use delimiters or ignore embedded instructions within extracted content.\n
  • Capability inventory: Code templates in references/knowledge/nlp/aimo-2-2025.md and references/knowledge/nlp/arc-prize-2025.md include subprocess.run(), exec(), requests.get(), and openai.chat.completions.create().\n
  • Sanitization: Absent; the skill suggests 'automatically adding' extracted knowledge to its permanent base without validation.\n- [DYNAMIC_EXECUTION]: The knowledge base provides several code templates that rely on dynamic execution of code strings generated at runtime. Specifically, references/knowledge/nlp/aimo-2-2025.md contains implementations for the MARIOFramework and solve_math_with_code_generation that use subprocess.run(['python', temp_file]) and exec(code, {}) to evaluate programmatically generated logic. This pattern is highly dangerous if the input used for code generation (extracted from external competition data) is attacker-controlled.\n- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and process content from Kaggle.com and references numerous third-party, non-vendor GitHub repositories for implementation patterns (e.g., github.com/VSydorskyy/BirdCLEF_2023_1st_place, github.com/LIHANG-HONG/birdclef2023-2nd-place-solution, github.com/AtsunoriFujita/BirdCLEF-2023-Identify-bird-calls-in-soundscapes). These repositories are hosted by individual users whose code has not been verified for security.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 08:02 AM