geopandas
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill implements a robust local-only data policy, explicitly rejecting URLs, remote URIs, and virtual filesystem paths (via
reject_nonlocalinscripts/_common.py). - [SAFE]: Extensive path validation is implemented to prevent path traversal and symlink attacks. All I/O is constrained within a configured root directory, and
..components or symlinks are strictly rejected through_candidate_pathand_reject_symlink_componentshelpers. - [SAFE]: Resource limits are enforced on input file sizes, feature counts, and output sizes to mitigate potential Denial of Service (DoS) attacks from malformed or excessively large geospatial data.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external vector data formats like GeoPackage and GeoParquet, which presents a theoretical attack surface for indirect prompt injection if an agent interprets metadata or attribute strings as instructions.
- Ingestion points: External vector files processed via
load_geodataframeandinspect_local_vectoracross all audit scripts. - Boundary markers: The skill generates structured JSON reports and provides instructions on redaction, although it does not implement LLM-specific boundary markers within the processed data files themselves.
- Capability inventory: The skill uses
Read,Write, andBashtools. It performs local file reads, basic metadata inspection, and restricted file writes (repairs). - Sanitization: All bundled CLI tools redact coordinates, identifiers, and sensitive field names by default. Error messages are also redacted at the CLI boundary to prevent information leakage.
- [COMMAND_EXECUTION]: The skill provides several Python CLI scripts intended for local auditing. These scripts are implemented with deterministic logic and avoid the use of dynamic execution (
evalorexec) on untrusted data.
Audit Metadata