ml-pipeline
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it ingests external data (CSV/Parquet) for model training and orchestration. However, it mitigates this risk by implementing a mandatory data validation layer using Great Expectations, which checks data schemas and distributions before processing.
- Ingestion points: Training data is ingested in
SKILL.md(viatrain_modelcomponent) andreferences/pipeline-orchestration.md(viaload_datatask). - Boundary markers: The skill utilizes explicit validation checkpoints and defines clear interfaces between pipeline stages.
- Capability inventory: The skill possesses capabilities for local file system writes (model serialization via
pickleandjoblib) and remote storage operations (uploading to Google Cloud Storage). - Sanitization: Data quality is strictly enforced using
Great Expectationsto ensure ingested content adheres to expected schemas. - [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted machine learning libraries and MLOps tools. These are standard industry dependencies and do not represent a security risk.
- Evidence: References to
mlflow,scikit-learn,pandas,great_expectations,torch, andgoogle-cloud-storageare used for their intended primary purposes. - [DYNAMIC_EXECUTION]: The skill uses
pickleandjoblibfor model serialization. While these can be unsafe if used with untrusted sources, the skill context is focused on internal pipeline orchestration where the developer controls the artifacts.
Audit Metadata