synthetic-data-generator
Warn
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill mandates the creation and execution of Python scripts in Step 3 to process large datasets using pandas and LLM endpoints. This dynamic code execution is required for the skill's batch processing functionality.
- [COMMAND_EXECUTION]: Step 4 details the use of browser automation via the chrome-devtools MCP server to fill online forms. It explicitly instructs the agent to employ techniques like randomized delays to evade anti-bot detection systems on third-party websites.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its 'Active Participant Simulator' feature. It ingests untrusted content from external web forms (Step 4.1) and processes it with high-privilege capabilities such as browser automation and Python script execution without explicit sanitization or boundary markers.
Audit Metadata