neurokit2
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements significant defensive programming in
scripts/_common.py, including root-jailing, symlink rejection, and path traversal prevention usingPath.resolve()andPath.relative_to(). - [SAFE]: The scripts include a mandatory
--deidentifiedflag for local data processing, prompting users to ensure data privacy before analysis. - [SAFE]: The skill uses strict I/O boundaries, rejecting URLs and network protocols in command-line arguments to prevent unauthorized data exfiltration.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external CSV data in scripts such as
ecg_hrv_pipeline.pyandeda_pipeline.py. - Ingestion points: Files are read via
read_numeric_columnsinscripts/_common.py. - Boundary markers: Delimiters are absent from the processed data streams.
- Capability inventory: The skill possesses file-write capabilities (e.g.,
write_csv,emit_json) but lacks dangerous dynamic execution or network outbound calls in the provided scripts. - Sanitization: Content is converted to floats and validated against a strict numeric schema, significantly reducing the risk of prompt injection from the data content.
- [INDIRECT_PROMPT_INJECTION]: The
SKILL.mdfile contains self-referential safety claims and instructions to disregard potential scanner findings (e.g., 'record it as a scanner false positive only after confirming no dynamic execution exists'), which targets the analysis process itself.
Audit Metadata