learn-datalake

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The shell script run.sh downloads and executes a script from https://astral.sh/uv/install.sh by piping it to sh. Although the source is the official domain for the well-known 'uv' tool, this pattern of remote script execution is a high-risk behavior.
  • [COMMAND_EXECUTION]: The skill acts as an orchestrator and extensively uses subprocess.run and subprocess.Popen to execute shell commands and trigger functionality in other skills (e.g., review-pdf, memory, table-lab). This is evident in learn_datalake.py, subprocess_exec.py, and learn_datalake/orchestrator.py.
  • [DYNAMIC_EXECUTION]: The module extractability_model.py uses pickle.load() to deserialize a machine learning model stored in the local state/ directory. Unsafe deserialization of local data can lead to arbitrary code execution if an attacker manages to modify the serialized file.
  • [CREDENTIALS_UNSAFE]: The scripts heal_analysis.py and heal_failures.py contain a hardcoded Bearer token sk-dev-proxy-123. This token is used to authenticate requests to a local service (SCILLM_URL) running on localhost:4001.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to download the 'uv' package manager installer from the internet during its setup phase.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — learn-datalake