csv-transformer
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard data processing command-line utilities such as
csvkit(e.g.,in2csv,csvcut,csvsql),qsv, andxan. These tools are used for their intended purpose of data transformation and validation. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process external CSV data, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: The skill processes external CSV files (SKILL.md).
- Boundary markers: No explicit instructions are provided to use delimiters or ignore embedded instructions within the data rows.
- Capability inventory: The skill uses subprocess calls to CLI tools and writes output files (SKILL.md).
- Sanitization: The workflow includes
csvcleanto validate CSV structure, though it does not specifically address instruction sanitization within the data content (SKILL.md).
Audit Metadata