build-ml-pipeline

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a set of best practices and architectural patterns for machine learning development. It does not contain any malicious instructions or obfuscated content.
  • [COMMAND_EXECUTION]: The skill mentions executing short Python probes and using environment managers like 'pixi'. It specifically restricts inline execution to 2 lines and requires the agent to obtain user confirmation before installing any missing dependencies, which serves as a security safeguard.
  • [EXTERNAL_DOWNLOADS]: The instructions reference loading data from external sources such as URLs, S3 buckets, and databases. These are standard operations for data science tasks and are presented as identifiers for the pipeline rather than as vectors for remote code execution.
  • [PROMPT_INJECTION]: While the skill uses strong imperative language and 'Stop conditions' to guide the agent's behavior, these instructions are focused on maintaining project-specific architecture and do not attempt to bypass the underlying model's safety filters or extract system prompts.
  • [DATA_EXFILTRATION]: No patterns of unauthorized data access or exfiltration were detected. The skill focuses on standard data handling practices within a research/development workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 03:59 PM
Security Audit — agent-trust-hub — build-ml-pipeline