harvard-artifacts-etl-analytics
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the user to clone a repository from an untrusted third-party GitHub account (
github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). Cloning and running unverified code (streamlit run app.py) from external sources poses a high risk of executing malicious logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests artifact metadata from the Harvard Art Museums API, which serves as an untrusted external data source that could contain malicious instructions.\n - Ingestion points: The
fetch_artifactsfunction inSKILL.mdretrieves data fromapi.harvardartmuseums.org.\n - Boundary markers: There are no boundary markers or instructions to isolate the external content from the agent's core instructions.\n
- Capability inventory: The skill has the capability to write to a SQL database (
load_metadata) and render content via a Streamlit dashboard.\n - Sanitization: While the code correctly uses parameterized SQL queries for database safety, it does not sanitize or filter the API content before it is displayed to the user or processed by the agent.\n- [METADATA_POISONING]: The skill claims to be provided by 'ara.so', which is inconsistent with the author context 'reason-machines', potentially misleading users about the source and safety of the instructions.
Recommendations
- AI detected serious security threats
Audit Metadata