scikit-learn

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides instructions and code examples for model persistence using libraries that perform unsafe deserialization.
  • Evidence: In references/model_evaluation.md, the skill demonstrates how to load models using joblib.load() and pickle.load() from local files.
  • Impact: These functions are susceptible to arbitrary code execution if the model files originate from an untrusted source or are tampered with.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Data is ingested via pd.read_csv('data.csv') in references/common_workflows.md and through various text feature extraction tools in references/preprocessing.md.
  • Capability inventory: The skill has the ability to write files (plot images) and execute Python scripts via the Bash tool.
  • Sanitization: No explicit logic is provided to sanitize or filter potential instructions embedded within the processed datasets.
  • Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores non-data content (like instructions) within the input files.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing several third-party Python packages for extended functionality.
  • Evidence: Documentation suggests installing imbalanced-learn, category-encoders, and umap-learn via uv pip.
  • Context: While these are well-known packages in the machine learning ecosystem, they represent an expanded dependency surface beyond the core scikit-learn library.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scikit-learn