scikit-learn
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides standalone Python scripts (scripts/classification_pipeline.py, scripts/clustering_analysis.py) and explicit instructions for the agent or user to execute them via the shell.\n- [DYNAMIC_EXECUTION]: The reference documentation in references/model_evaluation.md includes examples for model persistence using pickle.load() and joblib.load(). While these are standard tools in the scikit-learn ecosystem, they perform unsafe deserialization and can execute arbitrary code if used to load malicious files from untrusted sources.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data (e.g., CSV files) into the agent's context for processing. This presents a potential attack surface for indirect prompt injection if the data contains malicious instructions, particularly since no sanitization is performed on the input data.\n
- Ingestion points: Data is loaded via pd.read_csv('data.csv') and sklearn.datasets in SKILL.md, scripts/classification_pipeline.py, and multiple reference files.\n
- Boundary markers: The scripts and instructions do not include specific delimiters or warnings to the model to ignore potential instructions embedded within the training or test data.\n
- Capability inventory: The skill allows for local file creation (plt.savefig for generating plots) and console output of analysis results.\n
- Sanitization: The skill assumes the integrity of the data provided to the machine learning algorithms and does not perform validation or filtering of the input content.
Audit Metadata