data-science
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a startup instruction in
SKILL.mdthat directs the AI agent to execute a directory listing command (ls) to check for the presence of recommended companion skills in specific local configuration directories. - [EXTERNAL_DOWNLOADS]: The documentation provides installation instructions using the
npxpackage runner to download skills from theAbsolutelySkilledrepository, which serves as the distribution point for this suite of tools. - [SAFE]: The skill is designed to ingest and process external datasets, representing a potential surface for indirect prompt injection attacks. This is an expected and necessary characteristic for data analysis functionality.
- Ingestion points: Data is loaded from local CSV files using standard pandas methods (
pd.read_csv). - Boundary markers: No specific delimiters or safety instructions are defined for processing input data files.
- Capability inventory: The agent context allows for the execution of Python code and shell commands.
- Sanitization: While the skill provides templates for data cleaning (handling missing values, outliers, duplicates), it does not include specific sanitization against embedded malicious instructions in data fields.
Audit Metadata