earth2studio-data-fetch
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and lexicon files from
nvidia.github.ioandgithub.com/NVIDIA. These are official vendor resources for theearth2studioproject and are used to verify data source parameters and variable support. - [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation from GitHub and user-provided inputs to generate Python scripts. This creates a potential surface for indirect prompt injection if external content or user requests were to contain malicious instructions targeting the agent's code generation process. This is mitigated by the instruction to use trusted vendor documentation.
- Ingestion points: User-provided variables and times; documentation pages from
nvidia.github.ioandgithub.com/NVIDIA(specified inSKILL.md). - Boundary markers: None explicitly defined in the prompt instructions to delimit external documentation content.
- Capability inventory: The skill is designed to generate Python code based on the ingested data.
- Sanitization: No specific sanitization or filtering instructions are provided for the content retrieved from external documentation.
- [DATA_EXPOSURE]: The instructions mention
~/.cdsapircas a prerequisite for authenticating with CDS-based data sources. This is a standard configuration path for the Climate Data Store API and is mentioned only as a setup requirement for the user, with no instructions for the agent to read or exfiltrate the file content.
Audit Metadata