nixtla-baseline-review
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external CSV files, which creates a surface for indirect prompt injection.
- Ingestion points: Data is read from
nixtla_baseline_m4/results_*.csvvia the Read and Bash tools. - Boundary markers: The instructions do not include specific delimiters or warnings to the agent to ignore instructions embedded within the CSV file content.
- Capability inventory: The skill possesses the ability to read files, grep for patterns, and execute local bash commands.
- Sanitization: No explicit sanitization or validation of the CSV input data is performed before it is used to generate the final summary report.
- [COMMAND_EXECUTION]: The skill utilizes standard Unix command-line utilities such as
ls,head,cut,sort,wc, andgrepvia the Bash tool to discover files and calculate summary statistics. These operations are restricted to the local filesystem and intended for data analysis.
Audit Metadata