data-quality-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted datasets and business rules, interpolating results into an HTML report and a Markdown scorecard.
- Ingestion points: Multiple scripts (scripts/null_counter.py, scripts/duplicate_finder.py, scripts/referential_integrity.py, scripts/value_range_validator.py, and scripts/freshness_check.py) ingest external data using pandas.read_csv or pandas.read_parquet.
- Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore potentially malicious instructions embedded in the datasets being audited.
- Capability inventory: The skill is designed to generate deliverables by writing findings into assets/audit_report_template.html and assets/quality_rubric.md.
- Sanitization: The implementation lacks evident sanitization or escaping mechanisms for data points extracted from the dataset (e.g., sample values or column names) before they are included in generated reports.
Audit Metadata