skills/reason-machines/data-skills/harvard-art-museums-data-engineering-analytics/Gen Agent Trust Hub
harvard-art-museums-data-engineering-analytics
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's installation instructions direct the user to clone a repository from a personal GitHub account (
https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). Because this repository is not managed by a verified organization or the skill author, it represents an unverified external dependency that could be modified to include malicious code. - [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from an external API, creating a surface for potential indirect prompt injection.
- Ingestion points: Data is ingested from the Harvard Art Museums API in the
fetch_artifactsfunction withinSKILL.md. - Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore instructions embedded within the fetched artifact metadata.
- Capability inventory: The skill possesses the capability to write to a SQL database using
mysql-connector-pythonand execute analytical queries viapandas.read_sql. - Sanitization: The implementation uses
%splaceholders in theload_to_databasefunction, which provides standard protection against SQL injection for the data being loaded.
Audit Metadata