car-sales-data-engineering-analytics
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The installation instructions require cloning a repository from an untrusted personal GitHub account (
Abdumalik-ProDev/Car-Sales-Data-Engineering) and executing its contents usinguv run. This pattern enables the execution of arbitrary third-party code within the user's environment.\n- [EXTERNAL_DOWNLOADS]: The skill fetches its entire project structure and configuration from an external repository (https://github.com/Abdumalik-ProDev/Car-Sales-Data-Engineering.git) that is not associated with a recognized trusted organization or the skill's stated vendor.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data files, creating a vulnerability surface for indirect prompt injection.\n - Ingestion points: The skill loads data from
data/Car sales.csvusing theCarSalesAnalysisclass inSKILL.md.\n - Boundary markers: No delimiters or safety instructions are present to prevent the agent from obeying instructions embedded within the CSV data.\n
- Capability inventory: The skill possesses the ability to write to the file system (in the
outputs/directory) and launch a local network service (via Streamlit).\n - Sanitization: There is no evidence of content sanitization, validation, or filtering applied to the external data before it is processed or visualized.
Recommendations
- AI detected serious security threats
Audit Metadata