ai-data-analyst
Warn
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function involves the agent writing and executing self-contained Python scripts (analysis.py) on the local system. It also permits the execution of command-line tools such as bunx convex for backend operations and log analysis.
- [EXTERNAL_DOWNLOADS]: The implementation requires downloading and installing external software packages. This includes Python libraries specified in a requirements.txt file and Node.js tools via bunx, which fetches executable code from public registries.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external, potentially untrusted data files.
- Ingestion points: Data is ingested from CSV, Excel, JSON, and Parquet files, or via database connections during the analysis phase as described in SKILL.md.
- Boundary markers: The instructions do not specify the use of delimiters or instructions to ignore embedded commands to prevent the agent from obeying commands hidden within data.
- Capability inventory: The agent has access to full Python execution environments and specialized CLI tools for backend interaction (bunx convex).
- Sanitization: While the skill emphasizes data quality validation, it lacks specific measures to sanitize or escape natural language instructions that might be present in the data fields.
Audit Metadata