earth2studio-deterministic-forecast
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The evaluation setup script
evals/environment/setup/bootstrap.shmodifies the system-wide/etc/environmentfile. This action requires elevated privileges and includes a potential path injection vulnerability due to unsanitized environment variables. - [PERSISTENCE]: The
bootstrap.shscript appends configuration to/etc/environment, creating a persistent environment change that affects all shell sessions within the evaluation container. - [INDIRECT_PROMPT_INJECTION]: The skill uses user input to generate Python scripts that perform file system operations.
- Ingestion points: User requirements for variables, region, and time horizon.
- Boundary markers: None implemented.
- Capability inventory: File-writing via Earth2Studio IO backends like Zarr and NetCDF.
- Sanitization: No sanitization is performed on user-provided strings before inclusion in generated code.
Audit Metadata