ds-notebook-strict-code
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a potential attack surface through the ingestion of user-provided data science assignments and datasets as documented in SKILL.md. Boundary markers are present in the form of specific activation conditions that prioritize user requests for normal prose. The capability inventory is limited to standard agent interaction as no specific tools are requested in the YAML frontmatter. Sanitization is addressed via an explicit 'Anti-Patterns' instruction that warns the agent against treating external content, logs, or generated output as trusted instructions.
Audit Metadata