earth2studio-create-datasource
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of remote data store descriptions or URLs (Step 0) to guide implementation. While this represents a potential injection surface where malicious documentation could influence code generation, the risk is mitigated by the highly structured nature of the Earth2Studio framework and the inclusion of human-in-the-loop confirmation gates for the data source type and sanity-check results.
- Ingestion points: Step 0 in
SKILL.md(URL or description of remote data store). - Boundary markers: The skill uses template-based code generation (via
references/implementation-guide.py) which provides implicit structure. - Capability inventory: File writing (
earth2studio/data/*.py), shell command execution (uv,git,gh,make,pytest), and network operations (S3/HTTP data fetching and GitHub API interaction). - Sanitization: Not explicitly performed on the input description, relying instead on the agent's logic and user confirmation steps.
- [COMMAND_EXECUTION]: The skill utilizes standard development tools such as
git,gh(GitHub CLI), anduvto manage the codebase, run tests, and handle pull requests. These operations are essential for the skill's primary function and are performed within the context of the Earth2Studio repository. - [EXTERNAL_DOWNLOADS]: The skill fetches data from remote stores (S3, GCS, Azure, HTTP) during the validation phase (Step 12). This behavior is documented and necessary for validating that the newly created data source wrapper functions correctly. Evaluation targets use a placeholder S3 bucket (
s3://phoo-weather-data).
Audit Metadata