exploratory-data-analysis
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a well-documented tool designed for scientific data analysis. It operates locally on user-provided files and does not engage in suspicious network activity or hidden behavior.
- [EXTERNAL_DOWNLOADS]: The skill instructions and analysis script utilize a wide range of standard, well-known scientific Python libraries such as NumPy, Pandas, Biopython, HDF5, and Pillow. These are standard dependencies in the research community and are sourced from official package registries.
- [COMMAND_EXECUTION]: Data analysis is handled by a Python script (
eda_analyzer.py) that performs structural and statistical calculations. The script does not utilize dangerous functions likeeval()orexec(), nor does it execute arbitrary shell commands based on untrusted input. - [DATA_EXFILTRATION]: No network-enabled tools or patterns (such as
curl,requests, or socket operations) were found within the provided scripts. The skill's operations are confined to the local environment and the generated markdown reports. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a variety of external scientific data formats. While this naturally creates a potential surface for indirect prompt injection, the skill mitigates risk by performing analysis through a dedicated Python script that extracts metadata and statistics rather than interpreting the file content as instructions. The risk is considered minimal and inherent to the skill's primary function.
Audit Metadata