skills/reason-machines/data-skills/harvard-artifacts-collection-data-engineering/Gen Agent Trust Hub
harvard-artifacts-collection-data-engineering
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
incremental_loadfunction demonstrates a potential SQL injection vulnerability by using f-strings to interpolate thelast_update_datevariable directly into a SQL query string (WHERE lastupdate > '{last_update_date}'). If the input to this function is not strictly validated, it could allow arbitrary SQL command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest large amounts of artifact metadata from the Harvard Art Museums API and display it in a Streamlit dashboard.
- Ingestion points: Artifact metadata is fetched via
requests.getfromhttps://api.harvardartmuseums.org/objectand stored in a MySQL database. - Boundary markers: None identified in the provided code snippets.
- Capability inventory: The skill performs network operations (
requests.get), database writes (cursor.executemany), and data visualization (streamlit,plotly). - Sanitization: The
transform_artifactsmethod performs basic truncation ([:500]) and default value assignment, but does not sanitize content against embedded instructions that might influence an LLM if this skill's output is processed by one.
Audit Metadata