data-science

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a startup instruction in SKILL.md that directs the AI agent to execute a directory listing command (ls) to check for the presence of recommended companion skills in specific local configuration directories.
  • [EXTERNAL_DOWNLOADS]: The documentation provides installation instructions using the npx package runner to download skills from the AbsolutelySkilled repository, which serves as the distribution point for this suite of tools.
  • [SAFE]: The skill is designed to ingest and process external datasets, representing a potential surface for indirect prompt injection attacks. This is an expected and necessary characteristic for data analysis functionality.
  • Ingestion points: Data is loaded from local CSV files using standard pandas methods (pd.read_csv).
  • Boundary markers: No specific delimiters or safety instructions are defined for processing input data files.
  • Capability inventory: The agent context allows for the execution of Python code and shell commands.
  • Sanitization: While the skill provides templates for data cleaning (handling missing values, outliers, duplicates), it does not include specific sanitization against embedded malicious instructions in data fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — data-science