data-science
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to list files in various skill installation directories to determine if recommended companion skills are present.
- [EXTERNAL_DOWNLOADS]: The documentation provides commands to install additional related skills from the author's repository using the npx utility.
- [PROMPT_INJECTION]: The skill is designed to process external datasets such as CSV files; this ingestion of untrusted data into a coding environment constitutes a surface for indirect prompt injection if the data contains malicious instructions.
Audit Metadata