meridian-model-building
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill ingests and processes external data from CSV files to perform column mapping and data conversion. While it includes data quality guardrails (such as numeric validation and date parsing), processing untrusted tabular data is a consideration as the content could potentially influence the agent's heuristic mapping logic.
- Ingestion points: The skill reads header rows and data from user-provided CSV files in
SKILL.md(Step 2). - Boundary markers: The skill relies on structured templates but does not explicitly describe the use of unique delimiters for the ingested CSV content.
- Capability inventory: The skill possesses the capability to write files and execute Python scripts using shell commands as described in
SKILL.md(Step 7). - Sanitization: Data quality guardrails are defined in
references/csv_format_reference.md, including checks for numeric types, non-negative constraints, and date formatting. - Local Script Generation and Execution: A core feature of the skill is generating a Python script from templates and executing it. This involves assembling code dynamically and running it via a local interpreter. The skill incorporates mandatory interactive checkpoints at every major configuration step and before execution to ensure user oversight.
- Vendor-Specific Environment Usage: The skill references a specific execution path (
/tmp/meridian_eval_cache/bin/python3) and environment variables (BUILD_WORKSPACE_DIRECTORY). These patterns are consistent with the vendor's managed development and evaluation environments.
Audit Metadata