create-regressor

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses joblib.load to deserialize and restore trained models from the local filesystem. This function is inherently insecure when processing untrusted files and can lead to arbitrary code execution. Evidence: lib/storage.py (load_model).
  • [COMMAND_EXECUTION]: The skill communicates with other internal skills by executing their entry scripts via subprocess calls. Evidence: lib/memory_integration.py (recall_prior_regressors, learn_regressor_run) and scripts/assess_task.py (run_dogpile).
  • [DATA_EXFILTRATION]: Model training metrics and metadata are transmitted to a local memory service via HTTP POST requests for cross-skill persistence. Evidence: lib/storage.py (store_to_memory).
  • [PROMPT_INJECTION]: The skill ingests external tabular data that is summarized and persisted to the agent's memory, creating a surface for indirect prompt injection. Evidence: 1. Ingestion points: lib/data.py (load_data); 2. Boundary markers: Absent; 3. Capability inventory: subprocess.run (invoking the memory skill in lib/memory_integration.py); 4. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — create-regressor