harvard-art-museum-etl-analytics
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an unverified GitHub user.
- Evidence:
git clone https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.gitinSKILL.md. - [COMMAND_EXECUTION]: The skill provides shell commands for repository cloning and package installation.
- Evidence:
git clone,cd, andpip install -r requirements.txtcommands in the Setup section ofSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from an external API, creating a vulnerability surface for indirect instructions embedded in the artifact metadata.
- Ingestion points: The
fetch_artifactsandextract_all_artifactsfunctions inSKILL.mdretrieve JSON data fromapi.harvardartmuseums.org. - Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions embedded in the retrieved artifact metadata.
- Capability inventory: The skill has the capability to perform network requests (
requests.get), execute SQL queries (cursor.execute), and run shell commands (git clone,pip install). - Sanitization: The skill uses parameterization for API calls and SQL batch inserts (
executemany), which mitigates direct injection into those systems but does not prevent the LLM from being influenced by the content of the data processed during the analytics or visualization stages.
Audit Metadata