earth2studio-create-diagnostic

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external reference material (repositories, papers, or documentation) provided via URL or local path to define model parameters.
  • Ingestion points: The $ARGUMENTS variable in SKILL.md allows passing external URLs or file paths.
  • Boundary markers: There are no instructions to use delimiters or ignore instructions embedded within the provided reference materials.
  • Capability inventory: The agent has permissions to write Python source files to the repository, execute shell commands through uv run, and perform Git operations.
  • Sanitization: The skill lacks guidance on sanitizing or validating the contents of the reference material before processing.
  • [DYNAMIC_EXECUTION]: Multiple template files (references/skeleton-template.py, references/method-templates.py) and evaluation target scripts provide code that uses torch.load with the weights_only=False parameter. This configuration enables the deserialization of arbitrary Python objects using the pickle module, which is a known vector for arbitrary code execution if used on untrusted model checkpoints. Although SKILL.md mentions a warning, the default templates used by the agent include this unsafe configuration.
  • [METADATA_POISONING]: The skill exhibits inconsistent version metadata, with SKILL.md specifying version 0.16.0 while skill-card.md indicates 0.17.0. While not inherently malicious, such discrepancies can be used to mask the source or state of a skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:28 PM
Security Audit — agent-trust-hub — earth2studio-create-diagnostic