harvard-art-museums-data-engineering-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standard command-line instructions for environment setup, including cloning a GitHub repository and running a Streamlit application.
  • [EXTERNAL_DOWNLOADS]: The skill fetches artifact data from the official Harvard Art Museums API (https://api.harvardartmuseums.org/object) and installs standard Python libraries (streamlit, pandas, requests, etc.) from public registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an ingestion surface where it processes JSON data from an external API. While this creates a theoretical entry point for data-driven instructions, the skill uses structured parsing and database loading which minimizes the risk of unintended instruction execution.
  • [SAFE]: Credentials and secrets are managed via environment variables and .env file templates, following security best practices for local development.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:34 PM
Security Audit — agent-trust-hub — harvard-art-museums-data-engineering-pipeline