pymc
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: In references/workflows.md, the skill provides code examples for model serialization using Python's pickle module. While the documentation includes a specific warning to only unpickle trusted files and suggests NetCDF as a safer alternative, the inclusion of pickle.load() provides a vector for unsafe deserialization if applied to malicious local data.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied data for Bayesian analysis, creating an attack surface for indirect prompt injection.
- Ingestion points: Data is loaded into the agent's context through scripts like assets/linear_regression_template.py and assets/hierarchical_model_template.py using standard libraries like pandas.
- Boundary markers: The workflow does not explicitly implement delimiters or warnings to the agent regarding potential instructions embedded within the data.
- Capability inventory: The skill has access to shell tools (Bash), file modification (Write, Edit), and Python execution.
- Sanitization: There is no automated sanitization of data inputs to filter out non-numeric instructions.
Audit Metadata