data-analysis

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script scripts/analyze.py installs the duckdb and openpyxl packages from the official Python Package Index at runtime if they are not detected in the environment.
  • [COMMAND_EXECUTION]: The script uses subprocess.run to execute shell commands during the installation of its Python dependencies.
  • [DATA_EXFILTRATION]: The skill executes arbitrary SQL queries provided as command-line arguments. DuckDB's SQL engine includes native capabilities for reading and writing files (e.g., read_csv, st_read, COPY TO), which could be leveraged to access data outside the intended /mnt/user-data/uploads/ directory depending on the underlying environment permissions.
  • [PROMPT_INJECTION]: The skill processes untrusted user-uploaded data files and executes SQL queries based on their content. Additionally, SKILL.md contains a directive specifically instructing the agent not to read the Python implementation script (> [!NOTE] Do NOT read the Python file). This directive restricts the agent's ability to verify the safety and behavior of the underlying script.
  • Ingestion points: CSV and Excel files provided via the --files argument in scripts/analyze.py (file: scripts/analyze.py).
  • Boundary markers: None identified; file paths are passed directly from user context to the script.
  • Capability inventory: The skill can execute arbitrary SQL (which includes filesystem access via DuckDB functions), write files to the output directory, and execute shell commands for package management.
  • Sanitization: The script does not perform validation or sanitization of the internal structure or content of the data files before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — data-analysis