harvard-artifacts-data-engineering-streamlit
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of metadata from the Harvard Art Museums API, which is an external data source.\n
- Ingestion points:
fetch_artifactsandbatch_fetch_artifactsfunctions inSKILL.md.\n - Boundary markers: None present in the data transformation or display code.\n
- Capability inventory: Database writes via
mysql-connector-pythonand network requests viarequests.\n - Sanitization: The primary
load_to_databasefunction uses parameterized queries (%s), which provides protection against data-driven injection during the main ETL process.\n- [DYNAMIC_EXECUTION]: Thebuild_custom_queryfunction in the 'Advanced Features' section uses string interpolation to build SQL queries.\n - Evidence: Found in the 'Custom Query Builder' code snippet in
SKILL.md.\n - Description: The function constructs the query using f-strings for the
table,group_by, andfiltersparameters. Using string concatenation for SQL filters (e.g.,f\"{k}='{v}'\") is an unsafe pattern that could lead to SQL injection if these values are sourced from untrusted user input without validation.
Audit Metadata