tao-run-automl-deft-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external training datasets (CSV) and state files (JSON) as part of its AOI workflow. This represents an ingestion point for untrusted data that could theoretically contain embedded instructions targeting the agent's parsing logic.
  • [DYNAMIC_EXECUTION]: The skill provides Python code templates in its reference documentation (e.g., in references/phase-handoffs.md) designed to be executed by the agent to manipulate the deft_state.json file. While these are static templates for specific state transitions, they involve generating and running code at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:55 AM
Security Audit — agent-trust-hub — tao-run-automl-deft-pipeline