seaborn

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill manages environment setup by installing seaborn (version 0.13.2) along with optional statistical packages scipy and statsmodels using the uv package manager. These are well-known, established open-source libraries used extensively in the scientific computing community.\n- [EXTERNAL_DOWNLOADS]: The skill includes instructions for using sns.load_dataset(), which retrieves example datasets from the library's official public repository. This is a standard and expected feature of the Seaborn library for demonstration and testing purposes.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data via pandas.read_csv() and Seaborn's dataset loading functions. This creates a surface for indirect prompt injection if the processed data contains malicious instructions. However, the skill provides specific operating procedures for the agent to validate inputs and verify results, and the data processing capability is necessary for the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — seaborn