geopandas

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill implements a robust local-only data policy, explicitly rejecting URLs, remote URIs, and virtual filesystem paths (via reject_nonlocal in scripts/_common.py).
  • [SAFE]: Extensive path validation is implemented to prevent path traversal and symlink attacks. All I/O is constrained within a configured root directory, and .. components or symlinks are strictly rejected through _candidate_path and _reject_symlink_components helpers.
  • [SAFE]: Resource limits are enforced on input file sizes, feature counts, and output sizes to mitigate potential Denial of Service (DoS) attacks from malformed or excessively large geospatial data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external vector data formats like GeoPackage and GeoParquet, which presents a theoretical attack surface for indirect prompt injection if an agent interprets metadata or attribute strings as instructions.
  • Ingestion points: External vector files processed via load_geodataframe and inspect_local_vector across all audit scripts.
  • Boundary markers: The skill generates structured JSON reports and provides instructions on redaction, although it does not implement LLM-specific boundary markers within the processed data files themselves.
  • Capability inventory: The skill uses Read, Write, and Bash tools. It performs local file reads, basic metadata inspection, and restricted file writes (repairs).
  • Sanitization: All bundled CLI tools redact coordinates, identifiers, and sensitive field names by default. Error messages are also redacted at the CLI boundary to prevent information leakage.
  • [COMMAND_EXECUTION]: The skill provides several Python CLI scripts intended for local auditing. These scripts are implemented with deterministic logic and avoid the use of dynamic execution (eval or exec) on untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — geopandas