create-regressor
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
joblib.loadto deserialize and restore trained models from the local filesystem. This function is inherently insecure when processing untrusted files and can lead to arbitrary code execution. Evidence:lib/storage.py(load_model). - [COMMAND_EXECUTION]: The skill communicates with other internal skills by executing their entry scripts via subprocess calls. Evidence:
lib/memory_integration.py(recall_prior_regressors, learn_regressor_run) andscripts/assess_task.py(run_dogpile). - [DATA_EXFILTRATION]: Model training metrics and metadata are transmitted to a local memory service via HTTP POST requests for cross-skill persistence. Evidence:
lib/storage.py(store_to_memory). - [PROMPT_INJECTION]: The skill ingests external tabular data that is summarized and persisted to the agent's memory, creating a surface for indirect prompt injection. Evidence: 1. Ingestion points:
lib/data.py(load_data); 2. Boundary markers: Absent; 3. Capability inventory:subprocess.run(invoking thememoryskill inlib/memory_integration.py); 4. Sanitization: Absent.
Audit Metadata