harvard-art-museums-data-engineering-app

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a repository from an unverified GitHub account ('Manali0711'). Downloading and running code from unknown sources introduces a significant supply chain risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an ETL pipeline that ingests data from the Harvard Art Museums API and renders it in a Streamlit dashboard.
  • Ingestion points: Data is fetched from api.harvardartmuseums.org in the fetch_artifacts function.
  • Boundary markers: No delimiters or instructions are used to separate external data from agent commands.
  • Capability inventory: The skill uses requests for network access and mysql-connector-python for database operations.
  • Sanitization: There is no evidence of sanitization or filtering for potentially malicious strings within the API responses before they are displayed in the dashboard.
  • [COMMAND_EXECUTION]: The documentation includes shell commands for installation and execution (git clone, pip install, streamlit run) that result in the execution of third-party code and installation of remote packages.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-art-museums-data-engineering-app