earth2studio-create-diagnostic
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external reference material (repositories, papers, or documentation) provided via URL or local path to define model parameters.
- Ingestion points: The $ARGUMENTS variable in SKILL.md allows passing external URLs or file paths.
- Boundary markers: There are no instructions to use delimiters or ignore instructions embedded within the provided reference materials.
- Capability inventory: The agent has permissions to write Python source files to the repository, execute shell commands through uv run, and perform Git operations.
- Sanitization: The skill lacks guidance on sanitizing or validating the contents of the reference material before processing.
- [DYNAMIC_EXECUTION]: Multiple template files (references/skeleton-template.py, references/method-templates.py) and evaluation target scripts provide code that uses torch.load with the weights_only=False parameter. This configuration enables the deserialization of arbitrary Python objects using the pickle module, which is a known vector for arbitrary code execution if used on untrusted model checkpoints. Although SKILL.md mentions a warning, the default templates used by the agent include this unsafe configuration.
- [METADATA_POISONING]: The skill exhibits inconsistent version metadata, with SKILL.md specifying version 0.16.0 while skill-card.md indicates 0.17.0. While not inherently malicious, such discrepancies can be used to mask the source or state of a skill.
Audit Metadata