ai-data-analyst

Warn

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function involves the agent writing and executing self-contained Python scripts (analysis.py) on the local system. It also permits the execution of command-line tools such as bunx convex for backend operations and log analysis.
  • [EXTERNAL_DOWNLOADS]: The implementation requires downloading and installing external software packages. This includes Python libraries specified in a requirements.txt file and Node.js tools via bunx, which fetches executable code from public registries.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external, potentially untrusted data files.
  • Ingestion points: Data is ingested from CSV, Excel, JSON, and Parquet files, or via database connections during the analysis phase as described in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or instructions to ignore embedded commands to prevent the agent from obeying commands hidden within data.
  • Capability inventory: The agent has access to full Python execution environments and specialized CLI tools for backend interaction (bunx convex).
  • Sanitization: While the skill emphasizes data quality validation, it lacks specific measures to sanitize or escape natural language instructions that might be present in the data fields.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — ai-data-analyst