shap

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes a local Python script (scripts/tabular_report.py) and provides instructions to execute it using 'uv run'. This is an expected pattern for generating local data science reports and uses the skill's own template scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes machine learning datasets (tabular, text, images) which represents an attack surface for instructions embedded in external data.\n
  • Ingestion points: Data is loaded from CSV/JSON files or datasets like 'sklearn.datasets.load_breast_cancer' in 'scripts/tabular_report.py' and 'references/workflows.md'.\n
  • Boundary markers: Not present (typical for numerical data science tools).\n
  • Capability inventory: File writes (CSV, PNG, JSON), bash execution (uv pip install), and local script execution (uv run).\n
  • Sanitization: None; however, the skill focuses on numerical attribution and visualization, and includes warnings against deserializing untrusted binary artifacts (pickles), mitigating the highest risk paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — shap