csv-transformer

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard data processing command-line utilities such as csvkit (e.g., in2csv, csvcut, csvsql), qsv, and xan. These tools are used for their intended purpose of data transformation and validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process external CSV data, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: The skill processes external CSV files (SKILL.md).
  • Boundary markers: No explicit instructions are provided to use delimiters or ignore embedded instructions within the data rows.
  • Capability inventory: The skill uses subprocess calls to CLI tools and writes output files (SKILL.md).
  • Sanitization: The workflow includes csvclean to validate CSV structure, though it does not specifically address instruction sanitization within the data content (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 05:19 PM
Security Audit — agent-trust-hub — csv-transformer