harvard-artifacts-collection-analytics-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches artifact metadata and media information from the official Harvard Art Museums API (api.harvardartmuseums.org). This is a well-known service and the primary purpose of the skill.
  • [COMMAND_EXECUTION]: Provides standard instructions to clone the project repository from GitHub and install dependencies via the Python package manager (pip). These are typical developer workflow steps.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the museum API. However, it implements security best practices to mitigate injection risks by using parameterized queries (placeholders) when inserting data into the MySQL database.
  • [CREDENTIALS_UNSAFE]: Correctly instructs the user to store sensitive credentials like API keys and database passwords in a .env file rather than hardcoding them in the scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-artifacts-collection-analytics-pipeline