harvard-art-museums-data-engineering
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a project repository from a personal GitHub account (
https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). While GitHub is a well-known service, the repository is not from a verified organization. - [INDIRECT_PROMPT_INJECTION]: The skill processes and visualizes data from an external API (Harvard Art Museums), creating a surface for indirect prompt injection if the source data were to contain malicious instructions.
- Ingestion points: The
fetch_artifactsfunction inSKILL.mdretrieves metadata fromhttps://api.harvardartmuseums.org/object. - Boundary markers: The code does not implement explicit delimiters or instructions for the agent to ignore potentially malicious content embedded in the artifact titles or descriptions.
- Capability inventory: The skill possesses database write capabilities via
mysql-connector-python, network access throughrequests, and provides instructions for executing shell commands and Streamlit applications. - Sanitization: The
validate_artifactsfunction performs basic data cleaning such as handling missing values and duplicates, but it does not sanitize text for prompt injection vectors.
Audit Metadata