harvard-artifacts-collection-analytics-app
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the project source code from a repository on GitHub to initialize the application environment.\n
- Evidence:
git clone https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git\n- [COMMAND_EXECUTION]: Directs the user to install dependencies and launch the application using shell commands.\n - Evidence:
pip install -r requirements.txtandstreamlit run app.py\n- [INDIRECT_PROMPT_INJECTION]: The application ingests third-party data from the Harvard Art Museums API, which could potentially contain malicious instructions intended to influence an agent processing the dashboard output.\n - Ingestion points: API data is retrieved from
api.harvardartmuseums.orgwithin thefetch_artifactsfunction.\n - Boundary markers: The skill does not implement specific delimiters or warnings to isolate ingested data from agent instructions.\n
- Capability inventory: The skill writes data to a SQL database (
mysql-connector) and generates interactive visualizations (streamlit,plotly).\n - Sanitization: The provided code correctly uses parameterized SQL queries (
cursor.execute(query, tuple(row))), which prevents SQL injection attacks during the data loading phase.
Audit Metadata