exploratory-data-analysis

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze potentially untrusted scientific data files (CSV, TSV, JSON, HDF5, NumPy, FASTA, FASTQ, and various image formats). This creates an attack surface where malicious instructions could be embedded in dataset cells, headers, or metadata.
  • Ingestion points: Data is ingested through multiple scripts including scripts/eda_analyzer.py, scripts/tabular_profile.py, scripts/missingness_leakage_audit.py, scripts/distribution_sensitivity.py, scripts/sequence_inspector.py, and scripts/image_inspector.py.
  • Boundary markers: The skill contains explicit, non-negotiable instructions in SKILL.md and generated reports (assets/report_template.md) directing the agent to treat all file content as untrusted data and to never follow embedded instructions or resolve embedded URLs.
  • Capability inventory: The skill possesses Read, Write, Edit, Bash, and Glob capabilities. The associated Python scripts perform local file operations but do not include network access or arbitrary code execution paths.
  • Sanitization: The skill implements robust sanitization of identifiers and metadata using stable_token (pseudonymization), sanitize_identifier (printable character filtering), and markdown_scalar (strict character whitelisting for report generation). Furthermore, scripts/eda_analyzer.py escapes markdown and HTML control characters in aggregate data reports to prevent injection into the final report scaffold.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — exploratory-data-analysis