datasetlint
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the execution of shell commands including
datasetlint scan,go build, andbrew install. These are used to install, build, and run the auditing tool on local dataset files. - [EXTERNAL_DOWNLOADS]: The workflow describes downloading the
datasetlinttool either via Homebrew from the vendor's tap (itamaker/tap/datasetlint) or by cloning the source code from the vendor's GitHub repository (github.com/itamaker/datasetlint-skill). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external JSONL datasets. If these datasets contain malicious instructions, they could be included in the tool's output report (e.g., in
overlap_examplesorduplicate_samples), which might influence the agent's behavior during subsequent processing steps. - Ingestion points: Training and evaluation data provided as JSONL files via the
-trainand-evalflags. - Boundary markers: The tool relies on standard JSON structure for field delimitation but does not implement specific safety boundaries for the natural language content within those fields.
- Capability inventory: The skill executes the
datasetlintbinary, reads local files, and outputs text reports to the console. - Sanitization: The tool performs structural validation of JSON lines but does not sanitize the semantic content of the strings it compares and reports.
Audit Metadata