data-analytics-skills-claude
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as CSV files, SQL queries, and stakeholder requirements, which creates a surface for indirect prompt injection.
- Ingestion points: Data inputs via
pd.read_csv, SQL code blocks, and natural language business context provided in conversation. - Boundary markers: The documentation does not specify explicit delimiters or "ignore instructions" warnings for these inputs.
- Capability inventory: The skill prompts the agent to perform data manipulation (Pandas/Numpy), code analysis, and document generation based on inputs.
- Sanitization: No explicit sanitization or instruction-filtering is described for the processed content.
- [EXTERNAL_DOWNLOADS]: The documentation instructs the user to clone a repository from an unverified GitHub source (
https://github.com/nimrodfisher/data-analytics-skills.git) to obtain the skill library. - [COMMAND_EXECUTION]: The skill contains instructions for executing shell commands (
git clone) and Python code snippets for data analysis, which an autonomous agent might execute directly.
Audit Metadata