harvard-artifacts-collection-data-engineering-analytics

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a project from a personal GitHub repository (https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). This source is unverified and not associated with a trusted organization or the skill author.
  • [COMMAND_EXECUTION]: The project requires executing shell commands such as git clone, pip install, and streamlit run to download, install dependencies, and run the external application code.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an ETL pipeline that ingests artifact metadata from a public API (https://api.harvardartmuseums.org), which represents an attack surface for indirect instructions hidden in external data.
  • Ingestion points: External data enters the system through the fetch_artifacts_from_api function in SKILL.md.
  • Boundary markers: The code lacks boundary markers or explicit instructions to ignore potentially malicious commands embedded in the fetched JSON records.
  • Capability inventory: The skill possesses network access (requests), database interaction capabilities (mysql-connector-python), and data visualization tools (streamlit, plotly).
  • Sanitization: There is no evidence of sanitization or filtering of the API content beyond basic string truncation during the transformation step.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-artifacts-collection-data-engineering-analytics