exploratory-data-analysis

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a well-documented tool designed for scientific data analysis. It operates locally on user-provided files and does not engage in suspicious network activity or hidden behavior.
  • [EXTERNAL_DOWNLOADS]: The skill instructions and analysis script utilize a wide range of standard, well-known scientific Python libraries such as NumPy, Pandas, Biopython, HDF5, and Pillow. These are standard dependencies in the research community and are sourced from official package registries.
  • [COMMAND_EXECUTION]: Data analysis is handled by a Python script (eda_analyzer.py) that performs structural and statistical calculations. The script does not utilize dangerous functions like eval() or exec(), nor does it execute arbitrary shell commands based on untrusted input.
  • [DATA_EXFILTRATION]: No network-enabled tools or patterns (such as curl, requests, or socket operations) were found within the provided scripts. The skill's operations are confined to the local environment and the generated markdown reports.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a variety of external scientific data formats. While this naturally creates a potential surface for indirect prompt injection, the skill mitigates risk by performing analysis through a dedicated Python script that extracts metadata and statistics rather than interpreting the file content as instructions. The risk is considered minimal and inherent to the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — exploratory-data-analysis