data-analytics-skills-claude

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as CSV files, SQL queries, and stakeholder requirements, which creates a surface for indirect prompt injection.
  • Ingestion points: Data inputs via pd.read_csv, SQL code blocks, and natural language business context provided in conversation.
  • Boundary markers: The documentation does not specify explicit delimiters or "ignore instructions" warnings for these inputs.
  • Capability inventory: The skill prompts the agent to perform data manipulation (Pandas/Numpy), code analysis, and document generation based on inputs.
  • Sanitization: No explicit sanitization or instruction-filtering is described for the processed content.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs the user to clone a repository from an unverified GitHub source (https://github.com/nimrodfisher/data-analytics-skills.git) to obtain the skill library.
  • [COMMAND_EXECUTION]: The skill contains instructions for executing shell commands (git clone) and Python code snippets for data analysis, which an autonomous agent might execute directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — data-analytics-skills-claude