harvard-artifacts-collection-analytics-app

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the project source code from a repository on GitHub to initialize the application environment.\n
  • Evidence: git clone https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git\n- [COMMAND_EXECUTION]: Directs the user to install dependencies and launch the application using shell commands.\n
  • Evidence: pip install -r requirements.txt and streamlit run app.py\n- [INDIRECT_PROMPT_INJECTION]: The application ingests third-party data from the Harvard Art Museums API, which could potentially contain malicious instructions intended to influence an agent processing the dashboard output.\n
  • Ingestion points: API data is retrieved from api.harvardartmuseums.org within the fetch_artifacts function.\n
  • Boundary markers: The skill does not implement specific delimiters or warnings to isolate ingested data from agent instructions.\n
  • Capability inventory: The skill writes data to a SQL database (mysql-connector) and generates interactive visualizations (streamlit, plotly).\n
  • Sanitization: The provided code correctly uses parameterized SQL queries (cursor.execute(query, tuple(row))), which prevents SQL injection attacks during the data loading phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-artifacts-collection-analytics-app