car-sales-data-engineering-analytics

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation instructions require cloning a repository from an untrusted personal GitHub account (Abdumalik-ProDev/Car-Sales-Data-Engineering) and executing its contents using uv run. This pattern enables the execution of arbitrary third-party code within the user's environment.\n- [EXTERNAL_DOWNLOADS]: The skill fetches its entire project structure and configuration from an external repository (https://github.com/Abdumalik-ProDev/Car-Sales-Data-Engineering.git) that is not associated with a recognized trusted organization or the skill's stated vendor.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data files, creating a vulnerability surface for indirect prompt injection.\n
  • Ingestion points: The skill loads data from data/Car sales.csv using the CarSalesAnalysis class in SKILL.md.\n
  • Boundary markers: No delimiters or safety instructions are present to prevent the agent from obeying instructions embedded within the CSV data.\n
  • Capability inventory: The skill possesses the ability to write to the file system (in the outputs/ directory) and launch a local network service (via Streamlit).\n
  • Sanitization: There is no evidence of content sanitization, validation, or filtering applied to the external data before it is processed or visualized.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — car-sales-data-engineering-analytics