dask
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external datasets from potentially untrusted sources, creating an indirect prompt injection attack surface.
- Ingestion points: Data ingestion occurs in
SKILL.md,references/dataframes.md, andreferences/bags.mdthrough functions likedd.read_csv,dd.read_parquet, anddb.read_textwhich can ingest files, logs, and JSON records. - Boundary markers: The instructions do not define explicit boundary markers or delimiters to separate data from instructions during processing.
- Capability inventory: The skill has access to powerful tools including
Bashfor command execution andWritefor file system modifications. Dask itself provides capabilities to write data back to disk (to_parquet,to_csv,to_zarr) and execute custom Python functions across a cluster (client.submit,map_partitions). - Sanitization: There are no instructions for sanitizing or validating the content of the data being processed to prevent embedded malicious instructions from influencing agent behavior.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of standard data science libraries from public registries.
- Evidence:
SKILL.mdcontains instructions to installdask,s3fs,gcsfs, andpyarrowusinguv pip install. These are well-known, legitimate packages used in the data science ecosystem.
Audit Metadata