meridian-scenario-planner

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Script Generation and Execution: The skill is designed to create a Python script from a template and execute it to process binary model data. This is a core functional requirement and is performed using user-provided configurations and paths.
  • Interactive Checkpoints: The skill implements multiple 'CRITICAL INTERACTIVE CHECKPOINTs' that require the agent to pause and obtain user approval before configuring specs, writing files, or executing commands. This 'human-in-the-loop' approach provides significant oversight.
  • Indirect Prompt Injection Surface: The skill processes external binary model files, which represents a potential data ingestion surface. (1) Ingestion points: The model is loaded from a file (default meridian_model.binpb) using the meridian_serde library. (2) Boundary markers: While the binary content is not text-delimited, it is handled via specific serialization protocols. (3) Capability inventory: The agent has access to write_to_file and run_command to perform data processing. (4) Sanitization: The model data is processed using the vendor's internal schema and processors rather than being directly interpreted as instructions.
  • Resource Integrity: The skill interacts with official Google Meridian resources and provides a handoff to a trusted Google Colab environment, ensuring that the workflow remains within established platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:16 PM
Security Audit — agent-trust-hub — meridian-scenario-planner