harvard-art-museum-etl-analytics

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an unverified GitHub user.
  • Evidence: git clone https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git in SKILL.md.
  • [COMMAND_EXECUTION]: The skill provides shell commands for repository cloning and package installation.
  • Evidence: git clone, cd, and pip install -r requirements.txt commands in the Setup section of SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from an external API, creating a vulnerability surface for indirect instructions embedded in the artifact metadata.
  • Ingestion points: The fetch_artifacts and extract_all_artifacts functions in SKILL.md retrieve JSON data from api.harvardartmuseums.org.
  • Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions embedded in the retrieved artifact metadata.
  • Capability inventory: The skill has the capability to perform network requests (requests.get), execute SQL queries (cursor.execute), and run shell commands (git clone, pip install).
  • Sanitization: The skill uses parameterization for API calls and SQL batch inserts (executemany), which mitigates direct injection into those systems but does not prevent the LLM from being influenced by the content of the data processed during the analytics or visualization stages.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-art-museum-etl-analytics