harvard-art-museums-data-pipeline
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an unverified GitHub user ('Manali0711') using
git clone. This introduces a supply chain risk as the code and its future updates are not from a trusted organization or well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill implements a data pipeline that ingests artifact metadata from the Harvard Art Museums API.
- Ingestion points: Artifact data is fetched from
https://api.harvardartmuseums.org/objectinSKILL.md. - Boundary markers: None are present to delimit external data or warn the agent to ignore embedded instructions.
- Capability inventory: The skill uses
mysql-connector-pythonfor database writes andrequestsfor network operations. - Sanitization: There is no evidence of sanitization or filtering of the external API content beyond basic string length truncation (e.g.,
[:500]). If this data is subsequently processed by an LLM, it could trigger unintended behavior.
Audit Metadata