harvard-art-museums-etl-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a project repository from GitHub (https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). This is a standard project initialization step for this type of instructional skill.
  • [COMMAND_EXECUTION]: The skill includes shell commands for installing dependencies (pip install -r requirements.txt) and running the application (streamlit run app.py). These commands are typical for Streamlit-based data applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface by ingesting artifact metadata from the Harvard Art Museums API. However, the implementation utilizes parameterized SQL queries (using %s placeholders) which effectively mitigates the risk of data-driven SQL injection during the 'Load' phase of the ETL process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-art-museums-etl-analytics