harvard-artifacts-collection-analytics-etl
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a project repository from a personal GitHub account (
github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). While GitHub is a well-known service, the repository belongs to an untrusted individual author, which introduces a risk if the repository content is malicious. - [COMMAND_EXECUTION]: The installation and usage sections include instructions to execute shell commands, specifically
git clone,pip install -r requirements.txt, andstreamlit run app.py. These commands execute external code and scripts in the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill implements an ETL pipeline that ingests data from the Harvard Art Museums API (
api.harvardartmuseums.org). - Ingestion points: The
extract_artifactsfunction inSKILL.mdfetches artifact records from an external API. - Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore potentially malicious content within the museum data.
- Capability inventory: The skill uses
mysql-connector-pythonto write data to a SQL database andstreamlitto visualize the data. The execution environment also allows for general shell command execution as per the installation instructions. - Sanitization: The
transform_artifactsfunction performs basic string slicing (e.g.,[:500]) but lacks comprehensive sanitization or validation of the ingested JSON data to prevent downstream injection attacks or schema confusion.
Audit Metadata