harvard-artifacts-collection-etl-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The installation instructions include commands that execute git and pip. While standard for project setup, agents should be cautious when running these as they fetch and install external code.
  • [EXTERNAL_DOWNLOADS]: The skill fetches metadata from the Harvard Art Museums API (https://api.harvardartmuseums.org/object) and clones a repository from GitHub. These are well-known services and the downloads are consistent with the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted JSON data from an external API (Harvard Art Museums) and processes it through a transformation layer.
  • Ingestion points: API data is fetched via the fetch_artifacts function in SKILL.md.
  • Boundary markers: None identified; raw strings from JSON fields like description or title are stored directly in the database and later displayed in a Streamlit dashboard.
  • Capability inventory: The skill performs file system reads (environment variables), database writes (SQL inserts), and network operations (API requests).
  • Sanitization: The code uses basic Python .get() methods for JSON access but lacks explicit sanitization or filtering for potentially malicious instructions embedded in museum artifact metadata that could influence the LLM if it processes the database records.
  • [CREDENTIALS_UNSAFE]: The installation section provides examples of exporting sensitive environment variables such as DB_PASSWORD. While these are shown as placeholders (your_database_password), users should be reminded to never hardcode these in scripts or command history.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:34 PM
Security Audit — agent-trust-hub — harvard-artifacts-collection-etl-analytics