skills/reason-machines/data-skills/harvard-art-museums-data-engineering-pipeline/Gen Agent Trust Hub
harvard-art-museums-data-engineering-pipeline
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides standard command-line instructions for environment setup, including cloning a GitHub repository and running a Streamlit application.
- [EXTERNAL_DOWNLOADS]: The skill fetches artifact data from the official Harvard Art Museums API (
https://api.harvardartmuseums.org/object) and installs standard Python libraries (streamlit, pandas, requests, etc.) from public registries. - [INDIRECT_PROMPT_INJECTION]: The skill contains an ingestion surface where it processes JSON data from an external API. While this creates a theoretical entry point for data-driven instructions, the skill uses structured parsing and database loading which minimizes the risk of unintended instruction execution.
- [SAFE]: Credentials and secrets are managed via environment variables and
.envfile templates, following security best practices for local development.
Audit Metadata