harvard-art-museums-data-engineering-analytics

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installation instructions direct the user to clone a repository from a personal GitHub account (https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). Because this repository is not managed by a verified organization or the skill author, it represents an unverified external dependency that could be modified to include malicious code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from an external API, creating a surface for potential indirect prompt injection.
  • Ingestion points: Data is ingested from the Harvard Art Museums API in the fetch_artifacts function within SKILL.md.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore instructions embedded within the fetched artifact metadata.
  • Capability inventory: The skill possesses the capability to write to a SQL database using mysql-connector-python and execute analytical queries via pandas.read_sql.
  • Sanitization: The implementation uses %s placeholders in the load_to_database function, which provides standard protection against SQL injection for the data being loaded.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-art-museums-data-engineering-analytics