data-analysis
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The script
scripts/analyze.pyinstalls theduckdbandopenpyxlpackages from the official Python Package Index at runtime if they are not detected in the environment. - [COMMAND_EXECUTION]: The script uses
subprocess.runto execute shell commands during the installation of its Python dependencies. - [DATA_EXFILTRATION]: The skill executes arbitrary SQL queries provided as command-line arguments. DuckDB's SQL engine includes native capabilities for reading and writing files (e.g.,
read_csv,st_read,COPY TO), which could be leveraged to access data outside the intended/mnt/user-data/uploads/directory depending on the underlying environment permissions. - [PROMPT_INJECTION]: The skill processes untrusted user-uploaded data files and executes SQL queries based on their content. Additionally,
SKILL.mdcontains a directive specifically instructing the agent not to read the Python implementation script (> [!NOTE] Do NOT read the Python file). This directive restricts the agent's ability to verify the safety and behavior of the underlying script. - Ingestion points: CSV and Excel files provided via the
--filesargument inscripts/analyze.py(file:scripts/analyze.py). - Boundary markers: None identified; file paths are passed directly from user context to the script.
- Capability inventory: The skill can execute arbitrary SQL (which includes filesystem access via DuckDB functions), write files to the output directory, and execute shell commands for package management.
- Sanitization: The script does not perform validation or sanitization of the internal structure or content of the data files before processing.
Audit Metadata