harvard-artifacts-collection-analytics-etl

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a project repository from a personal GitHub account (github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). While GitHub is a well-known service, the repository belongs to an untrusted individual author, which introduces a risk if the repository content is malicious.
  • [COMMAND_EXECUTION]: The installation and usage sections include instructions to execute shell commands, specifically git clone, pip install -r requirements.txt, and streamlit run app.py. These commands execute external code and scripts in the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an ETL pipeline that ingests data from the Harvard Art Museums API (api.harvardartmuseums.org).
  • Ingestion points: The extract_artifacts function in SKILL.md fetches artifact records from an external API.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore potentially malicious content within the museum data.
  • Capability inventory: The skill uses mysql-connector-python to write data to a SQL database and streamlit to visualize the data. The execution environment also allows for general shell command execution as per the installation instructions.
  • Sanitization: The transform_artifacts function performs basic string slicing (e.g., [:500]) but lacks comprehensive sanitization or validation of the ingested JSON data to prevent downstream injection attacks or schema confusion.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-artifacts-collection-analytics-etl