csv-wrangling

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it is designed to process and analyze untrusted CSV data.
  • Ingestion points: The skill instructions involve processing external CSV, TSV, and SSV files as input for analysis (SKILL.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded prompts within the data are provided in the instructions.
  • Capability inventory: The skill utilizes a wide range of mcp__qsv__ tools for data transformation, SQL querying (sqlp), and AI-based documentation (describegpt), which could be influenced by malicious content in the processed data.
  • Sanitization: The skill does not describe or implement sanitization or validation of the content within the CSV files before processing.
  • [SAFE]: No explicit malicious code, obfuscation, or unauthorized exfiltration patterns were detected. The skill uses version-pinned references and standard tool interfaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:52 PM
Security Audit — agent-trust-hub — csv-wrangling