meridian-scenario-planner
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Script Generation and Execution: The skill is designed to create a Python script from a template and execute it to process binary model data. This is a core functional requirement and is performed using user-provided configurations and paths.
- Interactive Checkpoints: The skill implements multiple 'CRITICAL INTERACTIVE CHECKPOINTs' that require the agent to pause and obtain user approval before configuring specs, writing files, or executing commands. This 'human-in-the-loop' approach provides significant oversight.
- Indirect Prompt Injection Surface: The skill processes external binary model files, which represents a potential data ingestion surface. (1) Ingestion points: The model is loaded from a file (default
meridian_model.binpb) using themeridian_serdelibrary. (2) Boundary markers: While the binary content is not text-delimited, it is handled via specific serialization protocols. (3) Capability inventory: The agent has access towrite_to_fileandrun_commandto perform data processing. (4) Sanitization: The model data is processed using the vendor's internal schema and processors rather than being directly interpreted as instructions. - Resource Integrity: The skill interacts with official Google Meridian resources and provides a handoff to a trusted Google Colab environment, ensuring that the workflow remains within established platforms.
Audit Metadata