exploratory-data-analysis
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze potentially untrusted scientific data files (CSV, TSV, JSON, HDF5, NumPy, FASTA, FASTQ, and various image formats). This creates an attack surface where malicious instructions could be embedded in dataset cells, headers, or metadata.
- Ingestion points: Data is ingested through multiple scripts including
scripts/eda_analyzer.py,scripts/tabular_profile.py,scripts/missingness_leakage_audit.py,scripts/distribution_sensitivity.py,scripts/sequence_inspector.py, andscripts/image_inspector.py. - Boundary markers: The skill contains explicit, non-negotiable instructions in
SKILL.mdand generated reports (assets/report_template.md) directing the agent to treat all file content as untrusted data and to never follow embedded instructions or resolve embedded URLs. - Capability inventory: The skill possesses
Read,Write,Edit,Bash, andGlobcapabilities. The associated Python scripts perform local file operations but do not include network access or arbitrary code execution paths. - Sanitization: The skill implements robust sanitization of identifiers and metadata using
stable_token(pseudonymization),sanitize_identifier(printable character filtering), andmarkdown_scalar(strict character whitelisting for report generation). Furthermore,scripts/eda_analyzer.pyescapes markdown and HTML control characters in aggregate data reports to prevent injection into the final report scaffold.
Audit Metadata