skills/itamaker/skills/datasetlint/Gen Agent Trust Hub

datasetlint

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of shell commands including datasetlint scan, go build, and brew install. These are used to install, build, and run the auditing tool on local dataset files.
  • [EXTERNAL_DOWNLOADS]: The workflow describes downloading the datasetlint tool either via Homebrew from the vendor's tap (itamaker/tap/datasetlint) or by cloning the source code from the vendor's GitHub repository (github.com/itamaker/datasetlint-skill).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external JSONL datasets. If these datasets contain malicious instructions, they could be included in the tool's output report (e.g., in overlap_examples or duplicate_samples), which might influence the agent's behavior during subsequent processing steps.
  • Ingestion points: Training and evaluation data provided as JSONL files via the -train and -eval flags.
  • Boundary markers: The tool relies on standard JSON structure for field delimitation but does not implement specific safety boundaries for the natural language content within those fields.
  • Capability inventory: The skill executes the datasetlint binary, reads local files, and outputs text reports to the console.
  • Sanitization: The tool performs structural validation of JSON lines but does not sanitize the semantic content of the strings it compares and reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — datasetlint