scikit-survival
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes local CSV data, which constitutes a potential attack surface.
- Ingestion points: Data is loaded from local CSV files via the
read_csvfunction inscripts/_common.py. - Boundary markers: Absent; the skill processes structured tabular data for numerical modeling rather than text prompts.
- Capability inventory: The skill can write JSON, Markdown, and NumPy files to the local filesystem via utilities in
scripts/_common.py. - Sanitization: Mitigation includes strict row and feature count limits, data type validation, and the mandatory disabling of unsafe pickle deserialization.
- [DYNAMIC_EXECUTION]: The script
scripts/validate_survival_csv.pyperforms a dynamic import of the legitimate 'numpy' library for lazy calculation of a median value, which is a benign usage. - [SAFE]: The skill incorporates multiple proactive security measures. Input and output file utilities explicitly validate paths to reject network URLs and symbolic links. All NumPy load and save operations explicitly disable pickle (
allow_pickle=False) to prevent arbitrary code execution vulnerabilities. The skill also enforces strict bounds on input file size (32MB), row counts (20,000), and feature counts (256) to prevent resource exhaustion.
Audit Metadata