market-data-engineering

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions define clear, domain-specific workflows without any attempts to override system behavior or bypass safety filters.
  • [DATA_EXFILTRATION]: No sensitive file access (e.g., credentials, SSH keys) or unauthorized network operations were identified.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It uses a local Python diagnostic script with standard data processing libraries.
  • [COMMAND_EXECUTION]: Command execution is limited to running the local diagnostic script on user-provided data, which is consistent with the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external CSV data, the diagnostic script performs type coercion (converting data to numeric or datetime types), which effectively sanitizes the input and prevents the data from being interpreted as instructions by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 06:11 AM
Security Audit — agent-trust-hub — market-data-engineering