harvard-art-museum-etl-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a source code repository from a personal GitHub account (github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git).
  • [COMMAND_EXECUTION]: Provides instructions to install Python packages via a requirements file and execute a Streamlit web application, which runs code from the downloaded repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a pipeline that ingests data from an external source (Harvard Art Museums API).
  • Ingestion points: Data records fetched from api.harvardartmuseums.org in SKILL.md.
  • Boundary markers: Data is processed as structured JSON; however, there are no specific boundary delimiters or instructions for the agent to disregard potential instructions embedded within artifact metadata.
  • Capability inventory: The skill has the capability to write to a SQL database and render interactive charts in a web browser.
  • Sanitization: The provided code implementation uses parameterized SQL queries (%s placeholders) to mitigate database injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-art-museum-etl-pipeline