earth2studio-deterministic-forecast

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The evaluation setup script evals/environment/setup/bootstrap.sh modifies the system-wide /etc/environment file. This action requires elevated privileges and includes a potential path injection vulnerability due to unsanitized environment variables.
  • [PERSISTENCE]: The bootstrap.sh script appends configuration to /etc/environment, creating a persistent environment change that affects all shell sessions within the evaluation container.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses user input to generate Python scripts that perform file system operations.
  • Ingestion points: User requirements for variables, region, and time horizon.
  • Boundary markers: None implemented.
  • Capability inventory: File-writing via Earth2Studio IO backends like Zarr and NetCDF.
  • Sanitization: No sanitization is performed on user-provided strings before inclusion in generated code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:28 PM
Security Audit — agent-trust-hub — earth2studio-deterministic-forecast