earth2studio-create-prognostic

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes reference templates (references/skeleton-template.py and references/method-templates.py) that recommend the use of torch.load(..., weights_only=False). This configuration allows for the execution of arbitrary code during deserialization if a malicious model file is loaded, as it uses Python's pickle module without restrictions.
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves ingesting an external reference script (provided via $ARGUMENTS or a user-specified URL/path) to guide the implementation. Since this external content is analyzed by the agent to generate code and propose dependencies, it provides an entry point for embedded instructions to influence or hijack the agent's behavior during the task.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and interact with remote resources. This includes cloning the official earth2studio repository from GitHub and fetching model weights from services like HuggingFace, NGC, S3, and Google Cloud. An example also references fetching scripts from a third-party GitHub repository (github.com/198808xc/Pangu-Weather). While the platforms are well-known, fetching arbitrary scripts for analysis introduces supply chain risks.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute various shell commands through the uv tool, including running tests with pytest, executing make targets for linting and formatting, and managing dependencies. These operations grant the agent significant local execution capabilities within the workspace environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:27 PM
Security Audit — agent-trust-hub — earth2studio-create-prognostic