data-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements statistical rigor gates and pre-registration of metrics, which are industry best practices for preventing analytical bias and p-hacking.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute Python scripts for data processing and metric calculation. These scripts are constructed based on safe templates provided in the reference files (compute-examples.md and rigor-gates.md).
  • [DATA_EXFILTRATION]: No network-enabled tools are used, and no instructions for remote data transmission were found. The skill operates entirely on local datasets and generates local markdown artifacts.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns designed to bypass system constraints or safety filters. The use of natural language is strictly instructional and focused on data science methodology.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis: 1. Ingestion points: User-provided CSV and JSON files processed in Phase 3. 2. Boundary markers: The skill instructions focus on structural parsing rather than content isolation. 3. Capability inventory: The agent has access to Bash for computation and Write for file storage. 4. Sanitization: No explicit sanitization of data strings is mentioned. This represents a standard surface for data processing tools and is mitigated by the skill's focus on statistical aggregation rather than string interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 12:34 PM