neurokit2

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements significant defensive programming in scripts/_common.py, including root-jailing, symlink rejection, and path traversal prevention using Path.resolve() and Path.relative_to().
  • [SAFE]: The scripts include a mandatory --deidentified flag for local data processing, prompting users to ensure data privacy before analysis.
  • [SAFE]: The skill uses strict I/O boundaries, rejecting URLs and network protocols in command-line arguments to prevent unauthorized data exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external CSV data in scripts such as ecg_hrv_pipeline.py and eda_pipeline.py.
  • Ingestion points: Files are read via read_numeric_columns in scripts/_common.py.
  • Boundary markers: Delimiters are absent from the processed data streams.
  • Capability inventory: The skill possesses file-write capabilities (e.g., write_csv, emit_json) but lacks dangerous dynamic execution or network outbound calls in the provided scripts.
  • Sanitization: Content is converted to floats and validated against a strict numeric schema, significantly reducing the risk of prompt injection from the data content.
  • [INDIRECT_PROMPT_INJECTION]: The SKILL.md file contains self-referential safety claims and instructions to disregard potential scanner findings (e.g., 'record it as a scanner false positive only after confirming no dynamic execution exists'), which targets the analysis process itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — neurokit2