scikit-learn
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides instructions and code examples for model persistence using libraries that perform unsafe deserialization.
- Evidence: In
references/model_evaluation.md, the skill demonstrates how to load models usingjoblib.load()andpickle.load()from local files. - Impact: These functions are susceptible to arbitrary code execution if the model files originate from an untrusted source or are tampered with.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a surface for indirect prompt injection attacks.
- Ingestion points: Data is ingested via
pd.read_csv('data.csv')inreferences/common_workflows.mdand through various text feature extraction tools inreferences/preprocessing.md. - Capability inventory: The skill has the ability to write files (plot images) and execute Python scripts via the
Bashtool. - Sanitization: No explicit logic is provided to sanitize or filter potential instructions embedded within the processed datasets.
- Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores non-data content (like instructions) within the input files.
- [EXTERNAL_DOWNLOADS]: The skill recommends installing several third-party Python packages for extended functionality.
- Evidence: Documentation suggests installing
imbalanced-learn,category-encoders, andumap-learnviauv pip. - Context: While these are well-known packages in the machine learning ecosystem, they represent an expanded dependency surface beyond the core scikit-learn library.
Audit Metadata