scikit-learn

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standalone Python scripts (scripts/classification_pipeline.py, scripts/clustering_analysis.py) and explicit instructions for the agent or user to execute them via the shell.\n- [DYNAMIC_EXECUTION]: The reference documentation in references/model_evaluation.md includes examples for model persistence using pickle.load() and joblib.load(). While these are standard tools in the scikit-learn ecosystem, they perform unsafe deserialization and can execute arbitrary code if used to load malicious files from untrusted sources.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data (e.g., CSV files) into the agent's context for processing. This presents a potential attack surface for indirect prompt injection if the data contains malicious instructions, particularly since no sanitization is performed on the input data.\n
  • Ingestion points: Data is loaded via pd.read_csv('data.csv') and sklearn.datasets in SKILL.md, scripts/classification_pipeline.py, and multiple reference files.\n
  • Boundary markers: The scripts and instructions do not include specific delimiters or warnings to the model to ignore potential instructions embedded within the training or test data.\n
  • Capability inventory: The skill allows for local file creation (plt.savefig for generating plots) and console output of analysis results.\n
  • Sanitization: The skill assumes the integrity of the data provided to the machine learning algorithms and does not perform validation or filtering of the input content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:21 PM
Security Audit — agent-trust-hub — scikit-learn