data-formats

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes several unreferenced and bloated files (e.g., architecture-patterns.md, security-best-practices.md) that consist of 150 sections of repetitive filler text. This technique is characteristic of context window exhaustion or attention manipulation, potentially intended to obscure malicious instructions from analysis.\n- [REMOTE_CODE_EXECUTION]: Example server code for Arrow Flight binds to 0.0.0.0:8815 by default. This is an insecure practice that exposes the data transport service to all available network interfaces, significantly increasing the potential attack surface.\n- [REMOTE_CODE_EXECUTION]: The provided server-side code snippets for data ingestion lack validation or resource limits, such as maximum batch size or memory quotas. This makes the service vulnerable to memory exhaustion (Denial of Service) if deployed without modification.\n- [DATA_EXFILTRATION]: Reference documentation includes code for arbitrary network fetching (e.g., the concurrent_fetch function in testing-strategies.md). If used by an agent in a privileged environment, this could facilitate Server-Side Request Forgery (SSRF) or unauthorized data exfiltration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:21 PM
Security Audit — agent-trust-hub — data-formats